Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1110.001 Password Guessing |
MalwarePony | Pony has used a small dictionary of common passwords against a collected list of local accounts. |
| T1110.001 Password Guessing |
MalwareEmotet | Emotet has been observed using a hard coded list of passwords to brute force user accounts. |
| T1110.001 Password Guessing |
MalwareP.A.S. Webshell | P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services. |
| T1110.001 Password Guessing |
MalwareLucifer | Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords. |
| T1110.001 Password Guessing |
MalwareChina Chopper | China Chopper's server component can perform brute force password guessing against authentication portals. |
| T1110.001 Password Guessing |
MalwareXbash | Xbash can obtain a list of weak passwords from the C2 server to use for brute forcing as well as attempt to brute force services with open ports. |
| T1110.001 Password Guessing |
MalwareSpeakUp | SpeakUp can perform brute forcing using a pre-defined list of usernames and passwords in an attempt to log in to administrative panels. |
| T1110.001 Password Guessing |
MalwareHermeticWizard | HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares. |
| T1110.001 Password Guessing |
ToolCrackMapExec | CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.