ZeroHour
Palo Alto Unit 42published ()ingested Chao Lei, Zhibin Zhang, Aveek Das, Cecilia Hu

Mirai Variant MooBot Targeting D

mediumMalware exploited in the wildimportance 40CVE-2015-2051CVE-2018-6530CVE-2022-26258CVE-2022-28958
AI summary · glm-5.3-flash

Unit 42 observed the MooBot Mirai variant exploiting four D-Link vulnerabilities to compromise unpatched routers for use in DDoS attacks.

Unit 42 captured attacks exploiting four D-Link remote code execution vulnerabilities: CVE-2015-2051, CVE-2018-6530, CVE-2022-26258, and CVE-2022-28958, with three rated critical at CVSS 9.8. The exploits download the MooBot malware, a Mirai botnet variant, from infrastructure at 159.203.15.179 via wget. Compromised devices fall under full attacker control and can be used for distributed denial-of-service attacks. D-Link has published bulletins for all four flaws, but unpatched devices remain exposed.

  • Four D-Link vulnerabilities exploited; three rated CVSS 9.8 critical.
  • MooBot identified as a Mirai variant by the string w5q6he3dbrsgmclkiu4to18npavj702f.
  • Malware spawns randomly named processes and deletes its own executable.
  • Compromised devices can be used for DDoS attacks; patching strongly recommended.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-2051
Remote Command Execution via HNAP GetDeviceSettings in D-Link DIR-645 Router

The D-Link DIR-645 wired/wireless router is vulnerable to OS command injection (CWE-77) in its HNAP interface: input supplied to the GetDeviceSettings action is not properly neutralized, so a remote attacker who sends a crafted HTTP request to the router's HNAP endpoint can have arbitrary operating-system commands executed on the device. Successful exploitation gives the attacker control of the router at the system level, enabling reconfiguration or abuse of the device, traffic interception or redirection, and recruitment into IoT botnets, as reflected in recent Moobot/MooBot botnet campaigns. Any site or household still running a DIR-645, especially one whose web/HNAP management interface is reachable from the internet, is affected; the product is end-of-life. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile). CISA's required action reflects the risk: disconnect the impacted product if it is still in use because it has reached end-of-life.

Do: Because the DIR-645 is end-of-life, CISA's required action is to disconnect it; replace the device where possible, or at minimum apply the latest available D-Link firmware for the DIR-645 and ensure the management/HNAP interface is not reachable from the internet (block or restrict remote administration on the WAN side). Check the device for signs of botnet infection, such as unexpected outbound traffic or unexpected HNAP POST/SOAP requests, and prioritize this fix given the 97.1% EPSS score and known in-the-wild exploitation.

97% KEV
  • D-Link DIR-645 Wired/Wireless Router
largetens of thousands of internet-exposed devices (est.; far more DIR-645 units exist behind NAT given the product's broad consumer/SOHO distribution)
CVE-2018-6530
Unauthenticated OS Command Injection in D-Link DIR-860L/865L/868L/880L Routers

CVE-2018-6530 is an unauthenticated OS command injection flaw (CWE-78) in the SOAP interface (soap.cgi, handled by soapcgi_main in the cgibin binary) of several D-Link routers. A remote attacker sends a crafted request to soap.cgi containing a malicious 'service' parameter, causing arbitrary OS commands to execute on the router with no credentials or user interaction required. Successful exploitation yields full command execution on the device, enabling takeover, credential theft, or recruitment into botnets. Affected users are anyone running a D-Link DIR-860L, DIR-865L, DIR-868L, or DIR-880L on firmware at or below the versions listed in the advisory. Exploitation is active in the wild: CISA added the flaw to the KEV catalog on 2022-09-08 with known ransomware use, the Mirai variant MooBot/Moobot has been exploiting vulnerable D-Link routers to build botnets, and EPSS assigns a 96.7% probability of exploitation within 30 days (100th percentile).

Do: Apply the latest available firmware from D-Link — the vendor advisory states that the fix released under CVE-2018-20114 properly patches this vulnerability. Because all four affected models have reached end-of-life, CISA recommends disconnecting any affected device still in use if no supported firmware is available, and replacing it if it is internet-facing. As an interim mitigation, block or restrict WAN access to the router's web/SOAP (soap.cgi/HNAP) interface and check device logs for unexpected outbound connections indicative of MooBot/Mirai compromise.

9.897% KEV ransomware PoC
  • D-Link DIR-880L firmware DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and all previous versions
  • D-Link DIR-868L firmware DIR868LA1_FW112b04 and all previous versions
  • D-Link DIR-865L firmware DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and all previous versions
  • +1 more
massorder of 100,000+ internet-exposed devices, with total installed units across the four consumer router models plausibly in the millions (estimate)
CVE-2022-26258
Unauthenticated Remote Command Execution in D-Link DIR-820L Router

CVE-2022-26258 is an unauthenticated OS command injection (CWE-78) in D-Link DIR-820L router firmware, confirmed in version 1.05B03, reachable through the HTTP POST 'get set ccp' command interface. A remote attacker with no credentials and no user interaction can send a crafted HTTP POST request to this endpoint to execute arbitrary operating-system commands on the device. Successful exploitation yields full control of the router, providing a foothold for traffic interception, device enlistment into botnets, and lateral access to the home or small-office network behind it. Only users running the affected D-Link DIR-820L, an end-of-life consumer router, are affected, and no fixed firmware version is provided in the available data. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08 with a 92% EPSS score, and public reporting describes the Mirai-variant MooBot botnet targeting vulnerable D-Link devices.

Do: Because the DIR-820L is end-of-life and CISA's required action is to disconnect it if still in use, replace or retire the router; check the model and firmware version on the device's status/admin page (1.05B03 is confirmed vulnerable). If replacement is not immediate, disconnect the device from the internet or restrict exposure with firewall rules so the HTTP management interface is not reachable by untrusted hosts, and watch for Mirai-variant (MooBot) botnet traffic patterns. No fixed firmware version is provided in the available data, so upgrading alone is not a documented remedy.

9.892% KEV PoC ×2
  • D-Link DIR-820L router firmware 1.05B03 confirmed affected; the product is end-of-life and no fixed version is specified in the available data
large≈10,000–100,000 internet-exposed DIR-820L devices (order-of-magnitude estimate; a widely sold but end-of-life consumer router)
CVE-2022-28958
Rejected reason: DO NOT USE THIS CVE RECORD.

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

NVD description · AI analysis pending

Indicators of compromiseAll →

TypeIndicatorContext
domainkomaru.todayiguration decode function. After decoding its C2 server vpn.komaru[.]today from configuration, MooBot will send out a message to inf
domainwget.shompromised system and renames the binary files to Realtek . wget[.]sh 46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07
sha25606fc99956bd2afceebbcd157c71908f8ce9ddc81a830cbe86a2a3f4ff79da5f4A226EE541D7A0027C31FF05578E2 MooBot executable file. mipsel 06FC99956BD2AFCEEBBCD157C71908F8CE9DDC81A830CBE86A2A3F4FF79DA5F4 MooBot executable file. sh4 4BFF052C7FBF3F7AD025D7DBAB8BD98
sha256188bce5483a9bdc618e0ee9f3c961ff5356009572738ab703057857e8477a36b103F74397C46A21697B7D9C0448BE6 MooBot executable file. i686 188BCE5483A9BDC618E0EE9F3C961FF5356009572738AB703057857E8477A36B MooBot executable file. mips 4567979788B37FBED6EEDA02B3C15F
sha25636dcaf547c212b6228ca5a45a3f3a778271fbaf8e198ede305d801bc98893d5amised system, and renames the binary files to Android . arc 36DCAF547C212B6228CA5A45A3F3A778271FBAF8E198EDE305D801BC98893D5A MooBot executable file. arm 88B858B1411992509B0F2997877402D
sha2563b12aba8c92a15ef2a917f7c03a5216342e7d2626b025523c62308fc799b07373F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871 x86_64 3B12ABA8C92A15EF2A917F7C03A5216342E7D2626B025523C62308FC799B0737 Table 4. MooBot samples. Additional Resources New Mirai Var
sha2564567979788b37fbed6eeda02b3c15fafe3e0a226ee541d7a0027c31ff05578e26009572738AB703057857E8477A36B MooBot executable file. mips 4567979788B37FBED6EEDA02B3C15FAFE3E0A226EE541D7A0027C31FF05578E2 MooBot executable file. mipsel 06FC99956BD2AFCEEBBCD157C719
sha25646bb6e2f80b6cb96ff7d0f78b3bdbc496b69eb7f22ce15efcaa275f07cfae075system and renames the binary files to Realtek . wget[.]sh 46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07CFAE075 The script downloader. It downloads MooBot onto the comprom
sha2564bff052c7fbf3f7ad025d7dbab8bd985b6cac79381eb3f8616bef98fcb01d871E9DDC81A830CBE86A2A3F4FF79DA5F4 MooBot executable file. sh4 4BFF052C7FBF3F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871 MooBot executable file. x86_64 4BFF052C7FBF3F7AD025D7DBAB8B
sha2567123b2de979d85615c35fca99fa40e0b5fbca25f2c7654b083808653c9e4d61682902E538C2F7146C8666192893258 MooBot executable file. arm7 7123B2DE979D85615C35FCA99FA40E0B5FBCA25F2C7654B083808653C9E4D616 MooBot executable file. i586 CC3E92C52BBCF56CCFFB6F6E2942A6
sha25672153e51ea461452263dbb8f658bddc8fb82902e538c2f7146c866619289325849D3014776C1FB527C3B2E3086EBAB MooBot executable file. arm6 72153E51EA461452263DBB8F658BDDC8FB82902E538C2F7146C8666192893258 MooBot executable file. arm7 7123B2DE979D85615C35FCA99FA40E
sha25688b858b1411992509b0f2997877402d8bd9e378e4e21efe024d61e25b29daa0871FBAF8E198EDE305D801BC98893D5A MooBot executable file. arm 88B858B1411992509B0F2997877402D8BD9E378E4E21EFE024D61E25B29DAA08 MooBot executable file. arm5 D7564C7E6F606EC3A04BE3AC63FDEF
sha256b7ee57a42c6a4545ac6d6c29e1075fa1628e1d09b8c1572c848a70112d4c90a1own in the following table: File Name SHA256 Description rt B7EE57A42C6A4545AC6D6C29E1075FA1628E1D09B8C1572C848A70112D4C90A1 A script downloader. It downloads MooBot onto the compromis
sha256cc3e92c52bbcf56ccffb6f6e2942a676b3103f74397c46a21697b7d9c0448be6BCA25F2C7654B083808653C9E4D616 MooBot executable file. i586 CC3E92C52BBCF56CCFFB6F6E2942A676B3103F74397C46A21697B7D9C0448BE6 MooBot executable file. i686 188BCE5483A9BDC618E0EE9F3C961F
sha256d7564c7e6f606ec3a04be3ac63fdef2fde49d3014776c1fb527c3b2e3086ebab9E378E4E21EFE024D61E25B29DAA08 MooBot executable file. arm5 D7564C7E6F606EC3A04BE3AC63FDEF2FDE49D3014776C1FB527C3B2E3086EBAB MooBot executable file. arm6 72153E51EA461452263DBB8F658BDD
Full article1,149 words · extracted from unit42.paloaltonetworks.com · click to collapse

Executive Summary

In early August, Unit 42 researchers discovered attacks leveraging several vulnerabilities in devices made by D-Link, a company that specializes in network and connectivity products. The vulnerabilities exploited include:

  • CVE-2015-2051: D-Link HNAP SOAPAction Header Command Execution Vulnerability
  • CVE-2018-6530: D-Link SOAP Interface Remote Code Execution Vulnerability
  • CVE-2022-26258: D-Link Remote Command Execution Vulnerability
  • CVE-2022-28958: D-Link Remote Command Execution Vulnerability

If the devices are compromised, they will be fully controlled by attackers, who could utilize those devices to conduct further attacks such as distributed denial-of-service (DDoS) attacks. The exploit attempts captured by Unit 42 researchers leverage the aforementioned vulnerabilities to spread MooBot, a Mirai variant, which targets exposed networking devices running Linux.

While D-Link has published security bulletins regarding all the vulnerabilities mentioned here, some users may be running unpatched or older versions or devices. Unit 42 strongly recommends applying upgrades and patches where possible.

Palo Alto Networks Next-Generation Firewall customers receive protections through cloud-delivered security services such as IoT Security, Advanced Threat Prevention, WildFire and Advanced URL Filtering, which can detect and block the exploit traffic and malware.

Campaign Overview

The whole attack process is shown in Figure 1.

1. Attacker exploits vulnerable devices by leveraging CVE-2015-2051, CVE-2018-6530, CVE-2022-26528 and CVE-2022-28958. 2. The downloader requests MooBot binary from remote host. 3. Communication with C2 server. 4. The compromised devices launches an attack on other devices based on C2 command.
Figure 1. Campaign overview.

Exploited Vulnerabilities

Four known vulnerabilities were exploited in this attack. Upon successful exploitation, the wget utility executes to download MooBot samples from the malware infrastructure and then executes the downloaded binaries. Vulnerability-related information is shown in Table 1.

ID Vulnerability Description Severity
1 CVE-2015-2051 D-Link HNAP SOAPAction Header Command Execution Vulnerability CVSS Version 2.0: 10.0 High
2 CVE-2018-6530 D-Link SOAP Interface Remote Code Execution Vulnerability CVSS Version 3.0: 9.8 Critical
3 CVE-2022-26258 D-Link Remote Command Execution Vulnerability CVSS Version 3.0: 9.8 Critical
4 CVE-2022-28958 D-Link Remote Command Execution Vulnerability CVSS Version 3.0: 9.8 Critical

Table 1. List of exploited vulnerabilities.

D-Link Exploit Payloads

The attacker utilizes four D-Link vulnerabilities that could lead to remote code execution and download a MooBot downloader from host 159.203.15[.]179.

1. CVE-2015-2051: D-Link HNAP SOAPAction Header Command Execution Vulnerability

CVE-2015-2051 exploit payload, showing the connection to host 159.203.15[.]179, from which a MooBot downloader can be accessed.
Figure 2. CVE-2015-2051 exploit payload.

The exploit targeting the older D-Link routers takes advantage of vulnerabilities in the HNAP SOAP interface. An attacker can perform code execution through a blind OS command injection.

2. CVE-2018-6530: D-Link SOAP Interface Remote Code Execution Vulnerability

CVE-2018-6530 exploit payload, showing the connection to host 159.203.15[.]179, from which a MooBot downloader can be accessed.
Figure 3. CVE-2018-6530 exploit payload.

The exploit works due to the older D-Link router's unsanitized use of the “service” parameters in requests made to the SOAP interface. The vulnerability can be exploited to allow unauthenticated remote code execution.

3. CVE-2022-26258: D-Link Remote Code Execution Vulnerability

CVE-2022-26258 exploit payload, showing the connection to host 159.203.15[.]179, from which a MooBot downloader can be accessed.
Figure 4. CVE-2022-26258 exploit payload.

The exploit targets a command injection vulnerability in the /lan.asp component. The component does not successfully sanitize the value of the HTTP parameter DeviceName, which in turn can lead to arbitrary command execution.

4. CVE-2022-28958: D-Link Remote Code Execution Vulnerability

CVE-2022-28958 exploit payload, showing the connection to host 159.203.15[.]179, from which a MooBot downloader can be accessed.
Figure 5. CVE-2022-28958 exploit payload.

The exploit targets a remote command execution vulnerability in the /shareport.php component. The component does not successfully sanitize the value of the HTTP parameter value, which can lead to arbitrary command execution.

Malware Analysis

All the artifacts related to this attack are shown in the following table:

File Name SHA256 Description
rt B7EE57A42C6A4545AC6D6C29E1075FA1628E1D09B8C1572C848A70112D4C90A1 A script downloader. It downloads MooBot onto the compromised system and renames the binary files to Realtek
wget[.]sh 46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07CFAE075 The script downloader. It downloads MooBot onto the compromised system, and renames the binary files to Android.
arc 36DCAF547C212B6228CA5A45A3F3A778271FBAF8E198EDE305D801BC98893D5A MooBot executable file.
arm 88B858B1411992509B0F2997877402D8BD9E378E4E21EFE024D61E25B29DAA08 MooBot executable file.
arm5 D7564C7E6F606EC3A04BE3AC63FDEF2FDE49D3014776C1FB527C3B2E3086EBAB MooBot executable file.
arm6 72153E51EA461452263DBB8F658BDDC8FB82902E538C2F7146C8666192893258 MooBot executable file.
arm7 7123B2DE979D85615C35FCA99FA40E0B5FBCA25F2C7654B083808653C9E4D616 MooBot executable file.
i586 CC3E92C52BBCF56CCFFB6F6E2942A676B3103F74397C46A21697B7D9C0448BE6 MooBot executable file.
i686 188BCE5483A9BDC618E0EE9F3C961FF5356009572738AB703057857E8477A36B MooBot executable file.
mips 4567979788B37FBED6EEDA02B3C15FAFE3E0A226EE541D7A0027C31FF05578E2 MooBot executable file.
mipsel 06FC99956BD2AFCEEBBCD157C71908F8CE9DDC81A830CBE86A2A3F4FF79DA5F4 MooBot executable file.
sh4 4BFF052C7FBF3F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871 MooBot executable file.
x86_64 4BFF052C7FBF3F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871 MooBot executable file.

Table 2. Attack-related artifacts.

Unit 42 researchers conducted analysis on the downloaded malware sample. Based on its behavior and patterns, we believe that the malware samples that were hosted on 159.203.15[.]179 relate to a variant of the Mirai botnet called MooBot.

The most obvious feature of MooBot is the executable file containing the string w5q6he3dbrsgmclkiu4to18npavj702f, which will be used to generate random alphanumeric strings as shown.
Figure 6. MooBot random string generator.

The most obvious feature of MooBot is the executable file containing the string w5q6he3dbrsgmclkiu4to18npavj702f, which will be used to generate random alphanumeric strings.

Upon execution, the binary file prints get haxored! to the console, spawns processes with random names and wipes out the executable file.

The screenshot shows examples of MooBot spawning processes with random names.
Figure 7. MooBot creates processes.

As a variant, MooBot inherits Mirai’s most significant feature – a data section with embedded default login credentials and botnet configuration – but instead of using Mirai’s encryption key, 0xDEADBEEF, MooBot encrypts its data with 0x22.

Red arrows highlight the decode username and the decode password
Figure 8. MooBot configuration decode function.

After decoding its C2 server vpn.komaru[.]today from configuration, MooBot will send out a message to inform the C2 server that a new MooBot is online. The message starts with the hardcoded magic value 0x336699.

At the time of our analysis, the C2 server was offline. According to the code analysis, MooBot will also send heartbeat messages to the C2 server and parse commands from C2 to start a DDoS attack on a specific IP address and port number.

Conclusion

The vulnerabilities mentioned above have low attack complexity but critical security impact that can lead to remote code execution. Once the attacker gains control in this manner, they could take advantage by including the newly compromised devices into their botnet to conduct further attacks such as DDoS.

Therefore, we strongly recommend applying patches and upgrades when possible.

Palo Alto Networks customers receive protections from the vulnerability and malware through the following products and services:

  • Next-Generation Firewalls with a Threat Prevention security subscription can block the attacks with Best Practices via Threat Prevention signatures 38600, 92960, 92959 and 92533.
  • WildFire can stop the malware with static signature detections.
  • The Palo Alto Networks IoT security platform can leverage network traffic information to identify the vendor, model and firmware version of a device and identify specific devices that are vulnerable to the aforementioned CVEs.
  • Advanced URL Filtering and DNS Security are able to block the C2 domain and malware hosting URLs.
  • In addition, IoT Security has an inbuilt machine learning-based anomaly detection that can alert the customer if a device exhibits non-typical behavior, such as a sudden appearance of traffic from a new source, an unusually high number of connections or an inexplicable surge of certain attributes typically appearing in IoT application payloads.

Indicators of Compromise

Infrastructure

MooBot C2

vpn.komaru[.]today

Malware Host

http://159.203.15[.]179/wget.sh
http://159.203.15[.]179/wget.sh3
http://159.203.15[.]179/mips
http://159.203.15[.]179/mipsel
http://159.203.15[.]179/arm
http://159.203.15[.]179/arm5
http://159.203.15[.]179/arm6
http://159.203.15[.]179/arm7
http://159.203.15[.]179/sh4
http://159.203.15[.]179/arc
http://159.203.15[.]179/sparc
http://159.203.15[.]179/x86_64
http://159.203.15[.]179/i686
http://159.203.15[.]179/i586

Artifacts

Shell Script Downloader

Filename SHA256
rt B7EE57A42C6A4545AC6D6C29E1075FA1628E1D09B8C1572C848A70112D4C90A1
wget[.]sh 46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07CFAE075

Table 3. Shell script downloader.

MooBot Sample

Filename SHA256
arc 36DCAF547C212B6228CA5A45A3F3A778271FBAF8E198EDE305D801BC98893D5A
arm 88B858B1411992509B0F2997877402D8BD9E378E4E21EFE024D61E25B29DAA08
arm5 D7564C7E6F606EC3A04BE3AC63FDEF2FDE49D3014776C1FB527C3B2E3086EBAB
arm6 72153E51EA461452263DBB8F658BDDC8FB82902E538C2F7146C8666192893258
arm7 7123B2DE979D85615C35FCA99FA40E0B5FBCA25F2C7654B083808653C9E4D616
i586 CC3E92C52BBCF56CCFFB6F6E2942A676B3103F74397C46A21697B7D9C0448BE6
i686 188BCE5483A9BDC618E0EE9F3C961FF5356009572738AB703057857E8477A36B
mips 4567979788B37FBED6EEDA02B3C15FAFE3E0A226EE541D7A0027C31FF05578E2
mipsel 06FC99956BD2AFCEEBBCD157C71908F8CE9DDC81A830CBE86A2A3F4FF79DA5F4
sh4 4BFF052C7FBF3F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871
x86_64 3B12ABA8C92A15EF2A917F7C03A5216342E7D2626B025523C62308FC799B0737

Table 4. MooBot samples.

Additional Resources

New Mirai Variant Targeting Network Security Devices - Unit 42, Palo Alto Networks
Network Attack Trends: Internet of Threats (November 2020-January 2021) - Unit 42, Palo Alto Networks

Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/moobot-d-link-devices/