Password Guessing

T1110.001

Sub-technique of T1110 Brute Force.View on attack.mitre.org

About this technique

Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism. An adversary may guess login credentials without prior knowledge of system or environment passwords during an operation by using a list of common passwords. Password guessing may or may not take into account the target's policies on password complexity or use policies that may lock accounts out after a number of failed attempts.

Guessing passwords can be a risky option because it could cause numerous authentication failures and account lockouts, depending on the organization's login failure policies.

Typically, management services over commonly used ports are used when guessing passwords. Commonly targeted services include the following:

* SSH (22/TCP)
* Telnet (23/TCP)
* FTP (21/TCP)
* NetBIOS / SMB / Samba (139/TCP & 445/TCP)
* LDAP (389/TCP)
* Kerberos (88/TCP)
* RDP / Terminal Services (3389/TCP)
* HTTP/HTTP Management Services (80/TCP & 443/TCP)
* MSSQL (1433/TCP)
* Oracle (1521/TCP)
* MySQL (3306/TCP)
* VNC (5900/TCP)
* SNMP (161/UDP and 162/TCP/UDP)

In addition to management services, adversaries may "target single sign-on (SSO) and cloud-based applications utilizing federated authentication protocols," as well as externally facing email applications, such as Office 365.. Further, adversaries may abuse network device interfaces (such as `wlanAPI`) to brute force accessible wifi-router(s) via wireless authentication protocols.

In default environments, LDAP and Kerberos connection attempts are less likely to trigger events over SMB, which creates Windows "logon failure" event ID 4625.

Detection rules15

Rules on DetectionCode tagged with T1110.001.

Sigma3

RuleLevelLog source
HackTool - Hydra Password Bruteforce Executionhighwindows / process_creation
Suspicious Rejected SMB Guest Logon From IPmediumwindows / NULL
Suspicious Connection to Remote Accountlowwindows / ps_script

Splunk12

RuleTypeRiskData source
ASL AWS Credential Access GetPasswordDataAnomalyNULLASL AWS CloudTrail
AWS Credential Access Failed LoginTTPNULLAWS CloudTrail ConsoleLogin
AWS Credential Access GetPasswordDataAnomalyNULLAWS CloudTrail GetPasswordData
Azure AD High Number Of Failed Authentications For UserTTPNULLAzure Active Directory
Azure AD High Number Of Failed Authentications From IpTTPNULLAzure Active Directory
Azure AD Successful Authentication From Different IpsTTPNULLAzure Active Directory
Cisco ASA - User Account Lockout Threshold ExceededAnomalyNULLCisco ASA Logs
CrushFTP Max Simultaneous Users From IPAnomalyNULLCrushFTP
High Number of Login Failures from a single sourceAnomalyNULLO365 UserLoginFailed
O365 High Number Of Failed Authentications for UserTTPNULLO365 UserLoginFailed
Remote Desktop Network BruteforceTTPNULLSysmon EventID 3
Windows Remote Desktop Network Bruteforce AttemptAnomalyNULLSysmon EventID 3, Cisco Secure Access Firewall

Groups3

Software9

Campaigns0

None recorded.

Procedure examples12

Groups3

Used byProcedure example
GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks.

GroupAPT29

APT29 has successfully conducted password guessing attacks against a list of mailboxes.

GroupVOID MANTICORE

VOID MANTICORE has conducted password guessing to gain initial access.

Software9

Used byProcedure example
MalwareChina Chopper

China Chopper's server component can perform brute force password guessing against authentication portals.

ToolCrackMapExec

CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network.

MalwareEmotet

Emotet has been observed using a hard coded list of passwords to brute force user accounts.

MalwareHermeticWizard

HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares.

MalwareLucifer

Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords.

MalwareP.A.S. Webshell

P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services.

MalwarePony

Pony has used a small dictionary of common passwords against a collected list of local accounts.

MalwareSpeakUp

SpeakUp can perform brute forcing using a pre-defined list of usernames and passwords in an attempt to log in to administrative panels.

View all 9 software examples

References3

  1. Cylance Cleaver Open source
    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.
  2. Trend Micro Emotet 2020 Open source
    Cybercrime & Digital Threat Team. (2020, February 13). Emotet Now Spreads via Wi-Fi. Retrieved February 16, 2022.
  3. US-CERT TA18-068A 2018 Open source
    US-CERT. (2018, March 27). TA18-068A Brute Force Attacks Conducted by Cyber Actors. Retrieved October 2, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.