Using Kerberos for Authentication Relay Attacks
Common Information
Type Value
UUID 20806798-7b85-4d18-80d9-a3c0bf3aa8b2
Fingerprint 3698c9581a026c11
Analysis status DONE
Considered CTI value 1
Text language
Published Oct. 20, 2021, 9:26 a.m.
Added to db June 5, 2023, 10:50 a.m.
Last updated Nov. 14, 2024, 6:59 p.m.
Headline Project Zero
Title Using Kerberos for Authentication Relay Attacks
Detected Hints/Tags/Attributes 99/1/40
Attributes
Details Type #Events CTI Value
Details CVE 26
cve-2021-36942
Details Domain 1
fileserver.domain.com
Details Domain 70
evil.com
Details Domain 1
example.domain.com
Details Domain 9
www.evil.com
Details Domain 1
evilhost.domain.com
Details Domain 11
host.com
Details Domain 339
system.net
Details Email 1
password@host.com
Details File 14
lsasrv.dll
Details File 2
certcli.dll
Details File 2
dot3api.dll
Details File 1
dusmsvc.dll
Details File 1
frameserverclient.dll
Details File 1
l2sechc.dll
Details File 1
luiapi.dll
Details File 1
msdtcprx.dll
Details File 6
nlaapi.dll
Details File 1
ntfrsapi.dll
Details File 6
w32time.dll
Details File 1
wcnapi.dll
Details File 1
wcneapauthproxy.dll
Details File 1
wcneappeerproxy.dll
Details File 1
witnesswmiv2provider.dll
Details File 12
wlanapi.dll
Details File 4
wlanext.exe
Details File 1
wlanhc.dll
Details File 1
wlanmsm.dll
Details File 2
wlansvc.dll
Details File 2
wwansvc.dll
Details File 4
wwapi.dll
Details File 12
wldap32.dll
Details File 2
mrxsmb10.sys
Details File 2
mrxsmb20.sys
Details File 5
mrxsmb.sys
Details IPv4 1
10.0.0.80
Details Url 1
http://fileserver.domain.com
Details Url 1
http://domain\user:password@host.com
Details Url 1
http://evil.com\user:password@host.com
Details Url 1
http://www.evil.com