Sub-technique of T1016 System Network Configuration Discovery.View on attack.mitre.org
Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in numerous ways such as using Ping, tracert, and GET requests to websites, or performing initial speed testing to confirm bandwidth.
Adversaries may use the results and responses from these requests to determine if the system is capable of communicating with their C2 servers before attempting to connect to them. The results may also be used to identify routes, redirectors, and proxy servers.
Rules on DetectionCode tagged with T1016.001.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Network Discovery Using Route Windows App | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it. |
| GroupFIN13 | FIN13 has used `Ping` and `tracert` for network reconnaissance efforts. |
| GroupFIN8 | FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers. |
| GroupGamaredon Group | Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status. |
| GroupHAFNIUM | HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`. |
| GroupHEXANE | HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts. |
| GroupLotus Blossom | Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet. |
| GroupMagic Hound | Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity. |
| Used by | Procedure example |
|---|---|
| MalwareDarkTortilla | DarkTortilla can check for internet connectivity by issuing HTTP GET requests. |
| MalwareGoldFinder | GoldFinder performed HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request traveled through. |
| MalwareHavoc | The Havoc demon can check for a connection to the C2 server from the target machine. |
| MalwareMore_eggs | More_eggs has used HTTP GET requests to check internet connectivity. |
| MalwareNeoichor | Neoichor can check for Internet connectivity by contacting bing[.]com with the request format `bing[.]com?id=<GetTickCount>`. |
| MalwareNKAbuse | NKAbuse utilizes external services such as |
| MalwarePUBLOAD | PUBLOAD has identified internet connectivity details through commands such as `tracert -h 5 -4 google.com` and `curl http://myip.ipip.net`. |
| MalwareQakBot | QakBot can measure the download speed on a targeted host. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Wocao | During Operation Wocao, threat actors used a Visual Basic script that checked for internet connectivity. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.