ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1124×

83 examples

TechniqueUsed byProcedure example
T1124
System Time Discovery
MalwarePowerDuke

PowerDuke has commands to get the time the machine was built, the time, and the time zone.

T1124
System Time Discovery
MalwareGRIFFON

GRIFFON has used a reconnaissance module that can be used to retrieve the date and time of the system.

T1124
System Time Discovery
MalwareProxysvc

As part of the data reconnaissance phase, Proxysvc grabs the system time to send back to the control server.

T1124
System Time Discovery
MalwareTorisma

Torisma can collect the current time on a victim machine.

T1124
System Time Discovery
MalwareNOKKI

NOKKI can collect the current timestamp of the victim's machine.

T1124
System Time Discovery
MalwareStuxnet

Stuxnet collects the time and date of a system when it is infected.

T1124
System Time Discovery
MalwareAvosLocker

AvosLocker has checked the system time before and after encryption.

T1124
System Time Discovery
MalwarePAKLOG

PAKLOG has collected a timestamp to log the precise time a key was pressed, formatted as %Y-%m-%d %H:%M:%S.

T1124
System Time Discovery
MalwareWindTail

WindTail has the ability to generate the current date and time.

T1124
System Time Discovery
MalwareZeus Panda

Zeus Panda collects the current system time (UTC) and sends it back to the C2 server.

T1124
System Time Discovery
MalwareGravityRAT

GravityRAT can obtain the date and time of a system.

T1124
System Time Discovery
MalwareMedusa Ransomware

Medusa Ransomware has discovered device uptime through `GetTickCount()`.

T1124
System Time Discovery
MalwareAppleSeed

AppleSeed can pull a timestamp from the victim's machine.

T1124
System Time Discovery
MalwareCrimson

Crimson has the ability to determine the date and time on a compromised host.

T1124
System Time Discovery
MalwareDUSTTRAP

DUSTTRAP reads the infected system's current time and writes it to a log file during execution.

T1124
System Time Discovery
MalwareBADHATCH

BADHATCH can obtain the `DATETIME` and `UPTIME` from a compromised machine.

T1124
System Time Discovery
MalwarePUBLOAD

PUBLOAD has collected the machine’s tick count through the use of `GetTickCount`.

T1124
System Time Discovery
MalwareSystemBC

SystemBC has leveraged the time of the device to create a text file with a filename that uses the function of `uniqid(time()).‘.txt`, consisting of the 10 character UNIX timestamp and 13 hexadecimal characters.

T1124
System Time Discovery
MalwareShrinkLocker

ShrinkLocker retrieves a system timestamp that is used in generating an encryption key.

T1124
System Time Discovery
MalwareSombRAT

SombRAT can execute getinfo to discover the current time on a compromised host.

T1124
System Time Discovery
MalwareHOPLIGHT

HOPLIGHT has been observed collecting system time from victim machines.

T1124
System Time Discovery
MalwareInvisiMole

InvisiMole gathers the local system time from the victim’s machine.

T1124
System Time Discovery
MalwareOkrum

Okrum can obtain the date and time of the compromised system.

T1124
System Time Discovery
MalwareNightdoor

Nightdoor can identify the system local time information.

T1124
System Time Discovery
MalwareDCSrv

DCSrv can compare the current time on an infected host with a configuration value to determine when to start the encryption process.

T1124
System Time Discovery
MalwareDRATzarus

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to inspect system time.

T1124
System Time Discovery
MalwareConficker

Conficker uses the current UTC victim system date for domain generation and connects to time servers to determine the current date.

T1124
System Time Discovery
MalwareGreen Lambert

Green Lambert can collect the date and time from a compromised host.

T1124
System Time Discovery
MalwareGoldMax

GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server.

T1124
System Time Discovery
MalwareBeaverTail

BeaverTail has obtained and sent the current timestamp associated with the victim device to C2.

T1124
System Time Discovery
MalwareDarkWatchman

DarkWatchman can collect time zone information and system `UPTIME`.

T1124
System Time Discovery
MalwarePlugX

PlugX has identified system time through its GetSystemInfo command.

T1124
System Time Discovery
MalwareBisonal

Bisonal can check the system time set on the infected host.

T1124
System Time Discovery
MalwareEpic

Epic uses the net time command to get the system time from the machine and collect the current date and time zone information.

T1124
System Time Discovery
MalwareKEYPLUG

KEYPLUG can obtain the current tick count of an infected computer.

T1124
System Time Discovery
MalwareClambling

Clambling can determine the current time.

T1124
System Time Discovery
MalwareDarkGate

DarkGate creates a log file for capturing keylogging, clipboard, and related data using the victim host's current date for the filename. DarkGate queries victim system epoch time during execution. DarkGate captures system time information as part of automated profiling on initial installation.

T1124
System Time Discovery
MalwareSVCReady

SVCReady can collect time zone information.

T1124
System Time Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the current date and time on the compromised host.

T1124
System Time Discovery
MalwareLODEINFO

LODEINFO can capture system time to send to the C2.

T1124
System Time Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can execute GetLocalTime for time discovery.

T1124
System Time Discovery
MalwareBendyBear

BendyBear has the ability to determine local time on a compromised host.

T1124
System Time Discovery
MalwareGlassWorm

GlassWorm has the ability to check the system’s time zone on the victim device.

T1124
System Time Discovery
MalwareMetamorfo

Metamorfo uses JavaScript to get the system time.

T1124
System Time Discovery
MalwarePipeMon

PipeMon can send time zone information from a compromised host to C2.

T1124
System Time Discovery
MalwareT9000

T9000 gathers and beacons the system time during installation.

T1124
System Time Discovery
MalwareShamoon

Shamoon obtains the system time and will only activate if it is greater than a preset date.

T1124
System Time Discovery
MalwareBLUELIGHT

BLUELIGHT can collect the local time on a compromised host.

T1124
System Time Discovery
MalwareStoneDrill

StoneDrill can obtain the current date and time of the victim machine.

T1124
System Time Discovery
MalwareOopsIE

OopsIE checks to see if the system is configured with "Daylight" time and checks for a specific region to be set for the timezone.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.