ATT&CKSoftwareNet Crawler

Net Crawler

S0056

Malware.View on attack.mitre.org

About this malware

Net Crawler is an intranet worm capable of extracting credentials using credential dumpers and spreading to systems on a network over SMB by brute forcing accounts with recovered passwords and using PsExec to execute a copy of Net Crawler.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1003.001
LSASS Memory

Net Crawler uses credential dumpers such as Mimikatz and Windows Credential Editor to extract cached credentials from Windows systems.

T1021.002
SMB/Windows Admin Shares

Net Crawler uses Windows admin shares to establish authenticated sessions to remote systems over SMB as part of lateral movement.

T1110.002
Password Cracking

Net Crawler uses a list of known credentials gathered through credential dumping to guess passwords to accounts as it spreads throughout a network.

T1569.002
Service Execution

Net Crawler uses PsExec to perform remote service manipulation to execute a copy of itself as part of lateral movement.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cylance Cleaver Open source
    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.