Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1124 System Time Discovery |
MalwareSombRAT | SombRAT can execute |
| T1124 System Time Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed collecting system time from victim machines. |
| T1124 System Time Discovery |
MalwareInvisiMole | InvisiMole gathers the local system time from the victim’s machine. |
| T1124 System Time Discovery |
MalwareOkrum | Okrum can obtain the date and time of the compromised system. |
| T1124 System Time Discovery |
MalwareNightdoor | Nightdoor can identify the system local time information. |
| T1124 System Time Discovery |
MalwareDCSrv | DCSrv can compare the current time on an infected host with a configuration value to determine when to start the encryption process. |
| T1124 System Time Discovery |
MalwareDRATzarus | DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to inspect system time. |
| T1124 System Time Discovery |
MalwareConficker | Conficker uses the current UTC victim system date for domain generation and connects to time servers to determine the current date. |
| T1124 System Time Discovery |
MalwareGreen Lambert | Green Lambert can collect the date and time from a compromised host. |
| T1124 System Time Discovery |
MalwareGoldMax | GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server. |
| T1124 System Time Discovery |
MalwareBeaverTail | BeaverTail has obtained and sent the current timestamp associated with the victim device to C2. |
| T1124 System Time Discovery |
MalwareDarkWatchman | DarkWatchman can collect time zone information and system `UPTIME`. |
| T1124 System Time Discovery |
MalwarePlugX | PlugX has identified system time through its GetSystemInfo command. |
| T1124 System Time Discovery |
MalwareBisonal | Bisonal can check the system time set on the infected host. |
| T1124 System Time Discovery |
MalwareEpic | Epic uses the |
| T1124 System Time Discovery |
MalwareKEYPLUG | KEYPLUG can obtain the current tick count of an infected computer. |
| T1124 System Time Discovery |
MalwareClambling | Clambling can determine the current time. |
| T1124 System Time Discovery |
MalwareDarkGate | DarkGate creates a log file for capturing keylogging, clipboard, and related data using the victim host's current date for the filename. DarkGate queries victim system epoch time during execution. DarkGate captures system time information as part of automated profiling on initial installation. |
| T1124 System Time Discovery |
MalwareSVCReady | SVCReady can collect time zone information. |
| T1124 System Time Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the current date and time on the compromised host. |
| T1124 System Time Discovery |
MalwareLODEINFO | LODEINFO can capture system time to send to the C2. |
| T1124 System Time Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can execute |
| T1124 System Time Discovery |
MalwareBendyBear | BendyBear has the ability to determine local time on a compromised host. |
| T1124 System Time Discovery |
MalwareGlassWorm | GlassWorm has the ability to check the system’s time zone on the victim device. |
| T1124 System Time Discovery |
MalwareMetamorfo | Metamorfo uses JavaScript to get the system time. |
| T1124 System Time Discovery |
MalwarePipeMon | PipeMon can send time zone information from a compromised host to C2. |
| T1124 System Time Discovery |
MalwareT9000 | T9000 gathers and beacons the system time during installation. |
| T1124 System Time Discovery |
MalwareShamoon | Shamoon obtains the system time and will only activate if it is greater than a preset date. |
| T1124 System Time Discovery |
MalwareBLUELIGHT | BLUELIGHT can collect the local time on a compromised host. |
| T1124 System Time Discovery |
MalwareStoneDrill | StoneDrill can obtain the current date and time of the victim machine. |
| T1124 System Time Discovery |
MalwareOopsIE | OopsIE checks to see if the system is configured with "Daylight" time and checks for a specific region to be set for the timezone. |
| T1124 System Time Discovery |
MalwareRTM | RTM can obtain the victim time zone. |
| T1124 System Time Discovery |
MalwareGrandoreiro | Grandoreiro can determine the time on the victim machine via IPinfo. |
| T1124 System Time Discovery |
MalwareBazar | Bazar can collect the time on the compromised host. |
| T1124 System Time Discovery |
MalwareMoonWind | MoonWind obtains the victim's current time. |
| T1124 System Time Discovery |
Malwareccf32 | ccf32 can determine the local time on targeted machines. |
| T1124 System Time Discovery |
MalwareZebrocy | Zebrocy gathers the current time zone and date information from the system. |
| T1124 System Time Discovery |
MalwareSUNBURST | SUNBURST collected device `UPTIME`. |
| T1124 System Time Discovery |
MalwareEvilBunny | EvilBunny has used the API calls NtQuerySystemTime, GetSystemTimeAsFileTime, and GetTickCount to gather time metrics as part of its checks to see if the malware is running in a sandbox. |
| T1124 System Time Discovery |
MalwareTaidoor | Taidoor can use |
| T1124 System Time Discovery |
MalwareTajMahal | TajMahal has the ability to determine local time on a compromised host. |
| T1124 System Time Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers victim machine timezone information. |
| T1124 System Time Discovery |
MalwareCarbon | Carbon uses the command |
| T1124 System Time Discovery |
MalwareBISCUIT | BISCUIT has a command to collect the system `UPTIME`. |
| T1124 System Time Discovery |
MalwareFunnyDream | FunnyDream can check system time to help determine when changes were made to specified files. |
| T1124 System Time Discovery |
MalwareEgregor | Egregor contains functionality to query the local/system time. |
| T1124 System Time Discovery |
MalwareFELIXROOT | FELIXROOT gathers the time zone information from the victim’s machine. |
| T1124 System Time Discovery |
MalwareCannon | Cannon can collect the current time zone information from the victim’s machine. |
| T1124 System Time Discovery |
Malwarebuild_downer | build_downer has the ability to determine the local time to ensure malware installation only happens during the hours that the infected system is active. |
| T1124 System Time Discovery |
MalwareComRAT | ComRAT has checked the victim system's date and time to perform tasks during business hours (9 to 5, Monday to Friday). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.