ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1016×

232 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareTrickBot

TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine.

T1016
System Network Configuration Discovery
Malwarecd00r

cd00r can discover the IP for the network interface on the compromised device.

T1016
System Network Configuration Discovery
MalwarePowerDuke

PowerDuke has a command to get the victim's domain and NetBIOS name.

T1016
System Network Configuration Discovery
MalwareEKANS

EKANS can determine the domain of a compromised host.

T1016
System Network Configuration Discovery
MalwareBLINDINGCAN

BLINDINGCAN has collected the victim machine's local IP address information and MAC address.

T1016
System Network Configuration Discovery
MalwareNinja

Ninja can enumerate the IP address on compromised systems.

T1016
System Network Configuration Discovery
MalwarePikabot

Pikabot gathers victim network information through commands such as ipconfig and ipconfig /all.

T1016
System Network Configuration Discovery
MalwareAmadey

Amadey can identify the IP address of a victim machine.

T1016
System Network Configuration Discovery
MalwareProxysvc

Proxysvc collects the network adapter information and domain/username information based on current remote sessions.

T1016
System Network Configuration Discovery
MalwareOrz

Orz can gather victim proxy information.

T1016
System Network Configuration Discovery
MalwareTorisma

Torisma can collect the local MAC address using `GetAdaptersInfo` as well as the system's IP address.

T1016
System Network Configuration Discovery
MalwareNOKKI

NOKKI can gather information on the victim IP address.

T1016
System Network Configuration Discovery
Malwareyty

yty runs ipconfig /all and collects the domain name.

T1016
System Network Configuration Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the Internet adapter configuration.

T1016
System Network Configuration Discovery
MalwareStuxnet

Stuxnet collects the IP address of a compromised system.

T1016
System Network Configuration Discovery
MalwarePOWRUNER

POWRUNER may collect network configuration data by running ipconfig /all on a victim.

T1016
System Network Configuration Discovery
MalwareKOPILUWAK

KOPILUWAK can use Arp to discover a target's network configuration setttings.

T1016
System Network Configuration Discovery
MalwareSardonic

Sardonic has the ability to execute the `ipconfig` command.

T1016
System Network Configuration Discovery
MalwareEmissary

Emissary has the capability to execute the command ipconfig /all.

T1016
System Network Configuration Discovery
MalwareKEYMARBLE

KEYMARBLE gathers the MAC address of the victim’s machine.

T1016
System Network Configuration Discovery
MalwareRedLeaves

RedLeaves can obtain information about network parameters.

T1016
System Network Configuration Discovery
MalwareFelismus

Felismus collects the victim LAN IP address and sends it to the C2 server.

T1016
System Network Configuration Discovery
MalwareGeminiDuke

GeminiDuke collects information on network settings and Internet proxy settings from the victim.

T1016
System Network Configuration Discovery
MalwareHavoc

Havoc has a module for network enumeration including determining IP addresses.

T1016
System Network Configuration Discovery
MalwareGravityRAT

GravityRAT collects the victim IP address, MAC address, as well as the victim account domain name.

T1016
System Network Configuration Discovery
MalwareInvisibleFerret

InvisibleFerret has collected the local IP address, and external IP.

T1016
System Network Configuration Discovery
MalwareStrongPity

StrongPity can identify the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwarexCaon

xCaon has used the GetAdaptersInfo() API call to get the victim's MAC address.

T1016
System Network Configuration Discovery
MalwarePLAINTEE

PLAINTEE uses the ipconfig /all command to gather the victim’s IP address.

T1016
System Network Configuration Discovery
MalwareOceanSalt

OceanSalt can collect the victim’s IP address.

T1016
System Network Configuration Discovery
MalwareBrave Prince

Brave Prince gathers network configuration information as well as the ARP cache.

T1016
System Network Configuration Discovery
MalwareAppleSeed

AppleSeed can identify the IP of a targeted system.

T1016
System Network Configuration Discovery
MalwareNETWIRE

NETWIRE can collect the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareJ-magic

J-magic can compare the host and remote IPs to check if a received packet is from the infected machine.

T1016
System Network Configuration Discovery
MalwareiKitten

iKitten will look for the current IP address.

T1016
System Network Configuration Discovery
MalwareGomir

Gomir collects network information on infected systems such as listing interface names, MAC and IP addresses, and IPv6 addresses.

T1016
System Network Configuration Discovery
MalwareAria-body

Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host.

T1016
System Network Configuration Discovery
MalwareOlympic Destroyer

Olympic Destroyer uses API calls to enumerate the infected system's ARP table.

T1016
System Network Configuration Discovery
MalwareBOLDMOVE

BOLDMOVE enumerates network interfaces on the infected host.

T1016
System Network Configuration Discovery
MalwareCrimson

Crimson contains a command to collect the victim MAC address and LAN IP.

T1016
System Network Configuration Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate infected system network information.

T1016
System Network Configuration Discovery
MalwareTurian

Turian can retrieve the internal IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareMachete

Machete collects the MAC address of the target computer and other network configuration information.

T1016
System Network Configuration Discovery
MalwareAction RAT

Action RAT has the ability to collect the MAC address of an infected host.

T1016
System Network Configuration Discovery
MalwareAvenger

Avenger can identify the domain of the compromised host.

T1016
System Network Configuration Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about its IP addresses and MAC addresses.

T1016
System Network Configuration Discovery
MalwarePUBLOAD

PUBLOAD has obtained information about local networks through the `ipconfig /all` command.

T1016
System Network Configuration Discovery
MalwareGootloader

Gootloader can use an embedded script to check the IP address of potential victims visiting compromised websites.

T1016
System Network Configuration Discovery
MalwarePingPull

PingPull can retrieve the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareWellMess

WellMess can identify the IP address and user domain on the target machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.