System Time Discovery

T1124

Technique.View on attack.mitre.org

About this technique

An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such as the Windows Time Service on Windows or systemsetup on macOS. These time settings may also be synchronized between systems and services in an enterprise network, typically accomplished with a network time server within a domain.

System time information may be gathered in a number of ways, such as with Net on Windows by performing net time \\hostname to gather the system time on a remote system. The victim's time zone may also be inferred from the current system time or gathered by using w32tm /tz. In addition, adversaries can discover device uptime through functions such as GetTickCount() to determine how long it has been since the system booted up.

On network devices, Network Device CLI commands such as `show clock detail` can be used to see the current time configuration. On ESXi servers, `esxcli system clock get` can be used for the same purpose.

In addition, system calls – such as time() – have been used to collect the current time on Linux devices. On macOS systems, adversaries may use commands such as systemsetup -gettimezone or timeIntervalSinceNow to gather current time zone information or current date and time.

This information could be useful for performing other techniques, such as executing a file with a Scheduled Task/Job, or to discover locality information based on time zone to assist in victim targeting (i.e. System Location Discovery). Adversaries may also use knowledge of system time as part of a time bomb, or delaying execution until a specified date/time.

Detection rules4

Rules on DetectionCode tagged with T1124.

Sigma3

RuleLevelLog source
Use of W32tm as Timerhighwindows / process_creation
Cisco Discoverylowcisco / NULL
Discovery of a System Timelowwindows / process_creation

Splunk1

RuleTypeRiskData source
Windows System Time Discovery W32tm DelayAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups14

Software83

Show 59 more

Campaigns3

Procedure examples100

Groups14

Used byProcedure example
GroupBRONZE BUTLER

BRONZE BUTLER has used net time to check the local time on a target system.

GroupChimera

Chimera has used time /t and net time \\ip/hostname for system time discovery.

GroupCURIUM

CURIUM deployed mechanisms to check system time information following strategic website compromise attacks.

GroupDarkhotel

Darkhotel malware can obtain system time from a compromised host.

GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`.

GroupHigaisa

Higaisa used a function to gather the current time.

GroupKimsuky

Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`.

GroupLazarus Group

A Destover-like implant used by Lazarus Group can obtain the current system time and send it to the C2 server.

View all 14 groups examples

Software83

Used byProcedure example
MalwareAgent Tesla

Agent Tesla can collect the timestamp from the victim’s machine.

MalwareAppleSeed

AppleSeed can pull a timestamp from the victim's machine.

MalwareAstaroth

Astaroth collects the timestamp from the infected machine.

ToolAsyncRAT

AsyncRAT can check whether the current system hour and day of the week are within operating hours defined it its configuration.

MalwareAvosLocker

AvosLocker has checked the system time before and after encryption.

MalwareAzorult

Azorult can collect the time zone information from the system.

MalwareBADHATCH

BADHATCH can obtain the `DATETIME` and `UPTIME` from a compromised machine.

MalwareBazar

Bazar can collect the time on the compromised host.

View all 83 software examples

Campaigns3

Used byProcedure example
CampaignC0015

During C0015, the threat actors used the command `net view /all time` to gather the local time of a compromised network.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net time` command as part of their advanced reconnaissance.

CampaignOperation Wocao

During Operation Wocao, threat actors used the `time` command to retrieve the current time of a compromised system.

References12

  1. AnyRun TimeBomb Open source
    Malicious History. (2020, September 17). Time Bombs: Malware With Delayed Execution. Retrieved April 22, 2021.
  2. ESET DazzleSpy Jan 2022 Open source
    M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022.
  3. MAGNET GOBLIN Open source
    Check Point Research. (2024, March 8). MAGNET GOBLIN TARGETS PUBLICLY FACING SERVERS USING 1-DAY VULNERABILITIES. Retrieved March 27, 2024.
  4. MSDN System Time Open source
    Microsoft. (n.d.). System Time. Retrieved November 25, 2016.
  5. Mac Time Sync Open source
    Cone, Matt. (2021, January 14). Synchronize your Mac's Clock with a Time Server. Retrieved March 27, 2024.
  6. RSA EU12 They're Inside Open source
    Rivner, U., Schwartz, E. (2012). They’re Inside… Now What?. Retrieved November 25, 2016.
  7. System Information Discovery Technique Open source
    YUCEEL, Huseyin Can. Picus Labs. (2022, June 9). The System Information Discovery Technique Explained - MITRE ATT&CK T1082. Retrieved March 27, 2024.
  8. Technet Windows Time Service Open source
    Mathers, B. (2016, September 30). Windows Time Service Tools and Settings. Retrieved November 25, 2016.
  9. Virtualization/Sandbox Evasion Open source
    YUCEEL, Huseyin Can. Picus Labs. (2022, June 9). Virtualization/Sandbox Evasion - How Attackers Avoid Malware Analysis. Retrieved December 26, 2023.
  10. linux system time Open source
    ArchLinux. (2024, February 1). System Time. Retrieved March 27, 2024.
  11. show_clock_detail_cisco_cmd Open source
    Cisco. (2023, March 6). show clock detail - Cisco IOS Security Command Reference: Commands S to Z . Retrieved July 13, 2022.
  12. systemsetup mac time Open source
    Apple Support. (n.d.). About systemsetup in Remote Desktop. Retrieved March 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.