ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1110.001×

9 examples

TechniqueUsed byProcedure example
T1110.001
Password Guessing
MalwarePony

Pony has used a small dictionary of common passwords against a collected list of local accounts.

T1110.001
Password Guessing
MalwareEmotet

Emotet has been observed using a hard coded list of passwords to brute force user accounts.

T1110.001
Password Guessing
MalwareP.A.S. Webshell

P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services.

T1110.001
Password Guessing
MalwareLucifer

Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords.

T1110.001
Password Guessing
MalwareChina Chopper

China Chopper's server component can perform brute force password guessing against authentication portals.

T1110.001
Password Guessing
MalwareXbash

Xbash can obtain a list of weak passwords from the C2 server to use for brute forcing as well as attempt to brute force services with open ports.

T1110.001
Password Guessing
MalwareSpeakUp

SpeakUp can perform brute forcing using a pre-defined list of usernames and passwords in an attempt to log in to administrative panels.

T1110.001
Password Guessing
MalwareHermeticWizard

HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares.

T1110.001
Password Guessing
ToolCrackMapExec

CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.