Defaulting on Passwords (Part 1): r0_bot
概要
Early in March, while studying the ChinaZ threat, it became readily apparent that default passwords were being used for more than just a supplementary attack vector. Several bots relied heavily, if not exclusively, on systems with weak and/or default passwords to spread. We setup a system with weak and default passwords to capture any and all malware spread in this fashion. For this first test, I selected 5 sets of passwords; admin/admin, guest/guest, ubnt/ubnt, cisco/cisco and ADMIN/ADMIN (the last for picking up folks scanning for Supermicro IPMI devices). Unsurprisingly, it took just under 3 hours for the first infection to hit. What did surprise us though was what password combination was first to be hit; ubnt/ubnt.
Created: 2026-02-23
Indicators
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 8.16
Matched TTPs:
- T1689 - Downgrade Attack
- T1564.013 - Bind Mounts
MITREへのリンク →
Score: 6.14
Matched TTPs:
- T1564.013 - Bind Mounts
- T1097 - Pass the Ticket
MITREへのリンク →
Score: 6.14
Matched TTPs:
- T1097 - Pass the Ticket
- T1216 - System Script Proxy Execution
MITREへのリンク →
Score: 6.37
Matched TTPs:
- T1097 - Pass the Ticket
- T1599 - Network Boundary Bridging
MITREへのリンク →
Score: 7.06
Matched TTPs:
- T1097 - Pass the Ticket
- T1588.003 - Code Signing Certificates
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1061 - Graphical User Interface
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1599 - Network Boundary Bridging
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1599 - Network Boundary Bridging
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1055.005 - Thread Local Storage
MITREへのリンク →
Score: 7.75
Matched TTPs:
- T1055.005 - Thread Local Storage
- T1216 - System Script Proxy Execution
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1216 - System Script Proxy Execution
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1216 - System Script Proxy Execution
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.81
Matched TTPs:
- T1689 - Downgrade Attack
- T1564.013 - Bind Mounts
MITREへのリンク →
Score: 0.77
Matched TTPs:
- T1055.005 - Thread Local Storage
- T1216 - System Script Proxy Execution
MITREへのリンク →
Score: 0.72
Matched TTPs:
- T1588.003 - Code Signing Certificates
- T1097 - Pass the Ticket
MITREへのリンク →
Score: 0.63
Matched TTPs:
- T1097 - Pass the Ticket
- T1599 - Network Boundary Bridging
MITREへのリンク →
Score: 0.63
Matched TTPs:
- T1216 - System Script Proxy Execution
- T1097 - Pass the Ticket
MITREへのリンク →
Score: 0.59
Matched TTPs:
- T1097 - Pass the Ticket
- T1564.013 - Bind Mounts
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る