Real-world descriptions of how a group, tool or campaign used a technique.
83 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1124 System Time Discovery |
MalwarePowerDuke | PowerDuke has commands to get the time the machine was built, the time, and the time zone. |
| T1124 System Time Discovery |
MalwareGRIFFON | GRIFFON has used a reconnaissance module that can be used to retrieve the date and time of the system. |
| T1124 System Time Discovery |
MalwareProxysvc | As part of the data reconnaissance phase, Proxysvc grabs the system time to send back to the control server. |
| T1124 System Time Discovery |
MalwareTorisma | Torisma can collect the current time on a victim machine. |
| T1124 System Time Discovery |
MalwareNOKKI | NOKKI can collect the current timestamp of the victim's machine. |
| T1124 System Time Discovery |
MalwareStuxnet | Stuxnet collects the time and date of a system when it is infected. |
| T1124 System Time Discovery |
MalwareAvosLocker | AvosLocker has checked the system time before and after encryption. |
| T1124 System Time Discovery |
MalwarePAKLOG | PAKLOG has collected a timestamp to log the precise time a key was pressed, formatted as %Y-%m-%d %H:%M:%S. |
| T1124 System Time Discovery |
MalwareWindTail | WindTail has the ability to generate the current date and time. |
| T1124 System Time Discovery |
MalwareZeus Panda | Zeus Panda collects the current system time (UTC) and sends it back to the C2 server. |
| T1124 System Time Discovery |
MalwareGravityRAT | GravityRAT can obtain the date and time of a system. |
| T1124 System Time Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has discovered device uptime through `GetTickCount()`. |
| T1124 System Time Discovery |
MalwareAppleSeed | AppleSeed can pull a timestamp from the victim's machine. |
| T1124 System Time Discovery |
MalwareCrimson | Crimson has the ability to determine the date and time on a compromised host. |
| T1124 System Time Discovery |
MalwareDUSTTRAP | DUSTTRAP reads the infected system's current time and writes it to a log file during execution. |
| T1124 System Time Discovery |
MalwareBADHATCH | BADHATCH can obtain the `DATETIME` and `UPTIME` from a compromised machine. |
| T1124 System Time Discovery |
MalwarePUBLOAD | PUBLOAD has collected the machine’s tick count through the use of `GetTickCount`. |
| T1124 System Time Discovery |
MalwareSystemBC | SystemBC has leveraged the time of the device to create a text file with a filename that uses the function of `uniqid(time()).‘.txt`, consisting of the 10 character UNIX timestamp and 13 hexadecimal characters. |
| T1124 System Time Discovery |
MalwareShrinkLocker | ShrinkLocker retrieves a system timestamp that is used in generating an encryption key. |
| T1124 System Time Discovery |
MalwareSombRAT | SombRAT can execute |
| T1124 System Time Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed collecting system time from victim machines. |
| T1124 System Time Discovery |
MalwareInvisiMole | InvisiMole gathers the local system time from the victim’s machine. |
| T1124 System Time Discovery |
MalwareOkrum | Okrum can obtain the date and time of the compromised system. |
| T1124 System Time Discovery |
MalwareNightdoor | Nightdoor can identify the system local time information. |
| T1124 System Time Discovery |
MalwareDCSrv | DCSrv can compare the current time on an infected host with a configuration value to determine when to start the encryption process. |
| T1124 System Time Discovery |
MalwareDRATzarus | DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to inspect system time. |
| T1124 System Time Discovery |
MalwareConficker | Conficker uses the current UTC victim system date for domain generation and connects to time servers to determine the current date. |
| T1124 System Time Discovery |
MalwareGreen Lambert | Green Lambert can collect the date and time from a compromised host. |
| T1124 System Time Discovery |
MalwareGoldMax | GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server. |
| T1124 System Time Discovery |
MalwareBeaverTail | BeaverTail has obtained and sent the current timestamp associated with the victim device to C2. |
| T1124 System Time Discovery |
MalwareDarkWatchman | DarkWatchman can collect time zone information and system `UPTIME`. |
| T1124 System Time Discovery |
MalwarePlugX | PlugX has identified system time through its GetSystemInfo command. |
| T1124 System Time Discovery |
MalwareBisonal | Bisonal can check the system time set on the infected host. |
| T1124 System Time Discovery |
MalwareEpic | Epic uses the |
| T1124 System Time Discovery |
MalwareKEYPLUG | KEYPLUG can obtain the current tick count of an infected computer. |
| T1124 System Time Discovery |
MalwareClambling | Clambling can determine the current time. |
| T1124 System Time Discovery |
MalwareDarkGate | DarkGate creates a log file for capturing keylogging, clipboard, and related data using the victim host's current date for the filename. DarkGate queries victim system epoch time during execution. DarkGate captures system time information as part of automated profiling on initial installation. |
| T1124 System Time Discovery |
MalwareSVCReady | SVCReady can collect time zone information. |
| T1124 System Time Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the current date and time on the compromised host. |
| T1124 System Time Discovery |
MalwareLODEINFO | LODEINFO can capture system time to send to the C2. |
| T1124 System Time Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can execute |
| T1124 System Time Discovery |
MalwareBendyBear | BendyBear has the ability to determine local time on a compromised host. |
| T1124 System Time Discovery |
MalwareGlassWorm | GlassWorm has the ability to check the system’s time zone on the victim device. |
| T1124 System Time Discovery |
MalwareMetamorfo | Metamorfo uses JavaScript to get the system time. |
| T1124 System Time Discovery |
MalwarePipeMon | PipeMon can send time zone information from a compromised host to C2. |
| T1124 System Time Discovery |
MalwareT9000 | T9000 gathers and beacons the system time during installation. |
| T1124 System Time Discovery |
MalwareShamoon | Shamoon obtains the system time and will only activate if it is greater than a preset date. |
| T1124 System Time Discovery |
MalwareBLUELIGHT | BLUELIGHT can collect the local time on a compromised host. |
| T1124 System Time Discovery |
MalwareStoneDrill | StoneDrill can obtain the current date and time of the victim machine. |
| T1124 System Time Discovery |
MalwareOopsIE | OopsIE checks to see if the system is configured with "Daylight" time and checks for a specific region to be set for the timezone. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.