FORENSIA

ATT&CK · T1110.004 · sub-technique

Credential Stuffing

Tactics: credential-access

About

Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large numbers of username and password pairs are dumped online when a website or service is compromised and the user account credentials accessed. The information may be useful to an adversary attempting to compromise accounts by taking advantage of the tendency for users to use the same passwords across personal and business accounts. Credential stuffing is a risky option because it could cause numerous authentication failures and account lockouts, depending on the organization's login failure policies. Typically, management services over commonly used ports are used when stuffing credentials. Commonly targeted services include the following: * SSH (22/TCP) * Telnet (23/TCP) * FTP (21/TCP) * NetBIOS / SMB / Samba (139/TCP & 445/TCP) * LDAP (389/TCP) * Kerberos (88/TCP) * RDP / Terminal Services (3389/TCP) * HTTP/HTTP Management Services (80/TCP & 443/TCP) * MSSQL (1433/TCP) * Oracle (1521/TCP) * MySQL (3306/TCP) * VNC (5900/TCP) In addition to management services, adversaries may "target single sign-on (SSO) and cloud-based applications utilizing federated authentication protocols," as well as externally facing email applications, such as Office 365.

Platforms: Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, WindowsParent: T1110 Brute ForceMITRE ATT&CK ↗

Used by actors

2 known groups

Software

1 malware/tools implement this

TrickBot

Corpus indicators tagged with this technique

81 indicators in the corpus carry T1110.004.

IndicatorTypeFamilySevSrc
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
7f30259d72eb7432b2454c07be83365ecfa835188185b35b30d11654aadf86a0sha256phishing803
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
ea5d2096a2ef3dfe4fb870bd1f0270efaea993a6sha1phishing783
2ea61cdead470f570586f513e22d43d787befec6sha1phishing783
eb8ede7598220dbef28953dc7df2e5418d52fa36sha1phishing783
35f23dfb4135d4cd38a6a29e64d79191d166344dsha1phishing783
6a4cb1c75e1c59bbd4fbc4667f4c3bb5a74fe965sha1phishing783
cf3cbf93adf43d50618c88705857d3adb123ed24sha1phishing783
e9a44b3fe951cca57313533d6bc1d11e789c2018sha1phishing783
268a8420b791df46380ed9ad69905207e15d8a7csha1phishing781
f496736e2d2344de7963d4f722381f03227ec452sha1phishing783
1a37b674ed29c877890834e9aba616d9md5phishing763
7f74bb6ba185978134c318bc5f91d23cmd5phishing761
http://share.romnor.ca/gourlphishing753
http://sign.romnor.ca/gourlphishing753
http://verify.picis.net/verify-humanurlphishing753
http://briefing.romnor.ca/gourlphishing753
http://team.romnor.ca/gourlphishing753
http://download.romnor.ca/gourlphishing753
http://account.romnor.ca/gourlphishing753
216.180.245.166ipphishing703
83.136.211.85ipphishing703
193.8.187.42ipphishing701
188.227.196.240ipphishing703
vinicious.picis.netdomainphishing653

Showing the top 30 by severity of 81.