ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1124
System Time Discovery
MalwareSombRAT

SombRAT can execute getinfo to discover the current time on a compromised host.

T1124
System Time Discovery
MalwareHOPLIGHT

HOPLIGHT has been observed collecting system time from victim machines.

T1124
System Time Discovery
MalwareInvisiMole

InvisiMole gathers the local system time from the victim’s machine.

T1124
System Time Discovery
MalwareOkrum

Okrum can obtain the date and time of the compromised system.

T1124
System Time Discovery
MalwareNightdoor

Nightdoor can identify the system local time information.

T1124
System Time Discovery
MalwareDCSrv

DCSrv can compare the current time on an infected host with a configuration value to determine when to start the encryption process.

T1124
System Time Discovery
MalwareDRATzarus

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to inspect system time.

T1124
System Time Discovery
MalwareConficker

Conficker uses the current UTC victim system date for domain generation and connects to time servers to determine the current date.

T1124
System Time Discovery
MalwareGreen Lambert

Green Lambert can collect the date and time from a compromised host.

T1124
System Time Discovery
MalwareGoldMax

GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server.

T1124
System Time Discovery
MalwareBeaverTail

BeaverTail has obtained and sent the current timestamp associated with the victim device to C2.

T1124
System Time Discovery
MalwareDarkWatchman

DarkWatchman can collect time zone information and system `UPTIME`.

T1124
System Time Discovery
MalwarePlugX

PlugX has identified system time through its GetSystemInfo command.

T1124
System Time Discovery
MalwareBisonal

Bisonal can check the system time set on the infected host.

T1124
System Time Discovery
MalwareEpic

Epic uses the net time command to get the system time from the machine and collect the current date and time zone information.

T1124
System Time Discovery
MalwareKEYPLUG

KEYPLUG can obtain the current tick count of an infected computer.

T1124
System Time Discovery
MalwareClambling

Clambling can determine the current time.

T1124
System Time Discovery
MalwareDarkGate

DarkGate creates a log file for capturing keylogging, clipboard, and related data using the victim host's current date for the filename. DarkGate queries victim system epoch time during execution. DarkGate captures system time information as part of automated profiling on initial installation.

T1124
System Time Discovery
MalwareSVCReady

SVCReady can collect time zone information.

T1124
System Time Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the current date and time on the compromised host.

T1124
System Time Discovery
MalwareLODEINFO

LODEINFO can capture system time to send to the C2.

T1124
System Time Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can execute GetLocalTime for time discovery.

T1124
System Time Discovery
MalwareBendyBear

BendyBear has the ability to determine local time on a compromised host.

T1124
System Time Discovery
MalwareGlassWorm

GlassWorm has the ability to check the system’s time zone on the victim device.

T1124
System Time Discovery
MalwareMetamorfo

Metamorfo uses JavaScript to get the system time.

T1124
System Time Discovery
MalwarePipeMon

PipeMon can send time zone information from a compromised host to C2.

T1124
System Time Discovery
MalwareT9000

T9000 gathers and beacons the system time during installation.

T1124
System Time Discovery
MalwareShamoon

Shamoon obtains the system time and will only activate if it is greater than a preset date.

T1124
System Time Discovery
MalwareBLUELIGHT

BLUELIGHT can collect the local time on a compromised host.

T1124
System Time Discovery
MalwareStoneDrill

StoneDrill can obtain the current date and time of the victim machine.

T1124
System Time Discovery
MalwareOopsIE

OopsIE checks to see if the system is configured with "Daylight" time and checks for a specific region to be set for the timezone.

T1124
System Time Discovery
MalwareRTM

RTM can obtain the victim time zone.

T1124
System Time Discovery
MalwareGrandoreiro

Grandoreiro can determine the time on the victim machine via IPinfo.

T1124
System Time Discovery
MalwareBazar

Bazar can collect the time on the compromised host.

T1124
System Time Discovery
MalwareMoonWind

MoonWind obtains the victim's current time.

T1124
System Time Discovery
Malwareccf32

ccf32 can determine the local time on targeted machines.

T1124
System Time Discovery
MalwareZebrocy

Zebrocy gathers the current time zone and date information from the system.

T1124
System Time Discovery
MalwareSUNBURST

SUNBURST collected device `UPTIME`.

T1124
System Time Discovery
MalwareEvilBunny

EvilBunny has used the API calls NtQuerySystemTime, GetSystemTimeAsFileTime, and GetTickCount to gather time metrics as part of its checks to see if the malware is running in a sandbox.

T1124
System Time Discovery
MalwareTaidoor

Taidoor can use GetLocalTime and GetSystemTime to collect system time.

T1124
System Time Discovery
MalwareTajMahal

TajMahal has the ability to determine local time on a compromised host.

T1124
System Time Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers victim machine timezone information.

T1124
System Time Discovery
MalwareCarbon

Carbon uses the command net time \\127.0.0.1 to get information the system’s time.

T1124
System Time Discovery
MalwareBISCUIT

BISCUIT has a command to collect the system `UPTIME`.

T1124
System Time Discovery
MalwareFunnyDream

FunnyDream can check system time to help determine when changes were made to specified files.

T1124
System Time Discovery
MalwareEgregor

Egregor contains functionality to query the local/system time.

T1124
System Time Discovery
MalwareFELIXROOT

FELIXROOT gathers the time zone information from the victim’s machine.

T1124
System Time Discovery
MalwareCannon

Cannon can collect the current time zone information from the victim’s machine.

T1124
System Time Discovery
Malwarebuild_downer

build_downer has the ability to determine the local time to ensure malware installation only happens during the hours that the infected system is active.

T1124
System Time Discovery
MalwareComRAT

ComRAT has checked the victim system's date and time to perform tasks during business hours (9 to 5, Monday to Friday).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.