SMB/Windows Admin Shares

T1021.002

Sub-technique of T1021 Remote Services.View on attack.mitre.org

About this technique

Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.

SMB is a file, printer, and serial port sharing protocol for Windows machines on the same network or domain. Adversaries may use SMB to interact with file shares, allowing them to move laterally throughout a network. Linux and macOS implementations of SMB typically use Samba.

Windows systems have hidden network shares that are accessible only to administrators and provide the ability for remote file copy and other administrative functions. Example network shares include `C$`, `ADMIN$`, and `IPC$`. Adversaries may use this technique in conjunction with administrator-level Valid Accounts to remotely access a networked system over SMB, to interact with systems using remote procedure calls (RPCs), transfer files, and run transferred binaries through remote Execution. Example execution techniques that rely on authenticated sessions over SMB/RPC are Scheduled Task/Job, Service Execution, and Windows Management Instrumentation. Adversaries can also use NTLM hashes to access administrator shares on systems with Pass the Hash and certain configuration and patch levels.

Detection rules50

Rules on DetectionCode tagged with T1021.002.

Sigma36

RuleLevelLog source
CobaltStrike Service Installations - Systemcriticalwindows / NULL
Potential DCOM InternetExplorer.Application DLL Hijackcriticalwindows / file_event
Potential DCOM InternetExplorer.Application DLL Hijack - Image Loadcriticalwindows / image_load
Wmiprvse Wbemcomn DLL Hijack - Filecriticalwindows / file_event
CobaltStrike Service Installations - Securityhighwindows / NULL
DCOM InternetExplorer.Application Iertutil DLL Hijack - Securityhighwindows / NULL
First Time Seen Remote Named Pipehighwindows / NULL
First Time Seen Remote Named Pipe - Zeekhighzeek / NULL
HackTool - NetExec File Indicatorshighwindows / file_event
HackTool - SharpMove Tool Executionhighwindows / process_creation
Impacket PsExec Executionhighwindows / NULL
Metasploit Or Impacket Service Installation Via SMB PsExechighwindows / NULL
Metasploit SMB Authenticationhighwindows / NULL
Potential CobaltStrike Service Installations - Registryhighwindows / registry_set
Protected Storage Service Accesshighwindows / NULL

Splunk14

RuleTypeRiskData source
Detect PsExec With accepteula FlagTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Executable File Written in Administrative SMB ShareTTPNULLWindows Event Log Security 5145
Impacket Lateral Movement Commandline ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Impacket Lateral Movement smbexec CommandLine ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Impacket Lateral Movement WMIExec Commandline ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
SMB Traffic SpikeAnomalyNULL
SMB Traffic Spike - MLTKAnomalyNULL
Windows Alternate Data Stream Created Over Local ShareAnomalyNULLWindows Event Log Security 5145
Windows PUA Named PipeAnomalyNULLSysmon EventID 17, Sysmon EventID 18
Windows RMM Named PipeAnomalyNULLSysmon EventID 17, Sysmon EventID 18
Windows Special Privileged Logon On Multiple HostsTTPNULLWindows Event Log Security 4672
Windows Suspicious C2 Named PipeTTPNULLSysmon EventID 17, Sysmon EventID 18
Windows Suspicious Named PipeTTPNULLSysmon EventID 17, Sysmon EventID 18
Windows Theme File Creation in Unusual LocationAnomalyNULLSysmon EventID 11

Groups27

Show 3 more

Software30

Show 6 more

Campaigns8

Procedure examples65

Groups27

Used byProcedure example
GroupAPT28

APT28 has mapped network drives using Net and administrator credentials.

GroupAPT3

APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement.

GroupAPT32

APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution.

GroupAPT39

APT39 has used SMB for lateral movement.

GroupAPT41

APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI).

GroupAquatic Panda

Aquatic Panda used remote shares to enable lateral movement in victim environments.

GroupBlackByte

BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.

GroupBlue Mockingbird

Blue Mockingbird has used Windows Explorer to manually copy malicious files to remote hosts over SMB.

View all 27 groups examples

Software30

Used byProcedure example
MalwareAnchor

Anchor can support windows execution via SMB shares.

MalwareBlackByte Ransomware

BlackByte Ransomware uses mapped shared folders to transfer ransomware payloads via SMB.

MalwareBlackEnergy

BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares.

ToolBrute Ratel C4

Brute Ratel C4 has the ability to use SMB to pivot in compromised networks.

MalwareCobalt Strike

Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement.

MalwareConficker

Conficker variants spread through NetBIOS share propagation.

MalwareConti

Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network.

MalwareDiavol

Diavol can spread throughout a network via SMB prior to encryption.

View all 30 software examples

Campaigns8

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team utilized `net use` to connect to network shares.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 leveraged SMB to transfer files and move laterally.

CampaignCutting Edge

During Cutting Edge, threat actors moved laterally using compromised credentials to connect to internal Windows systems with SMB.

CampaignHomeLand Justice

During HomeLand Justice, threat actors used SMB for lateral movement.

CampaignLeviathan Australian Intrusions

Leviathan used remote shares to move laterally through victim networks during Leviathan Australian Intrusions.

CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used SMB to pivot internally in victim networks.

CampaignOperation Wocao

During Operation Wocao, threat actors used Impacket's smbexec.py as well as accessing the C$ and IPC$ shares to move laterally.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users.

References3

  1. Microsoft Admin Shares Open source
    Microsoft. (n.d.). How to create and delete hidden or administrative shares on client computers. Retrieved November 20, 2014.
  2. TechNet RPC Open source
    Microsoft. (2003, March 28). What Is RPC?. Retrieved June 12, 2016.
  3. Wikipedia Server Message Block Open source
    Wikipedia. (2017, December 16). Server Message Block. Retrieved December 21, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.