Technique.View on attack.mitre.org
An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such as the Windows Time Service on Windows or systemsetup on macOS. These time settings may also be synchronized between systems and services in an enterprise network, typically accomplished with a network time server within a domain.
System time information may be gathered in a number of ways, such as with Net on Windows by performing net time \\hostname to gather the system time on a remote system. The victim's time zone may also be inferred from the current system time or gathered by using w32tm /tz. In addition, adversaries can discover device uptime through functions such as GetTickCount() to determine how long it has been since the system booted up.
On network devices, Network Device CLI commands such as `show clock detail` can be used to see the current time configuration. On ESXi servers, `esxcli system clock get` can be used for the same purpose.
In addition, system calls – such as time() – have been used to collect the current time on Linux devices. On macOS systems, adversaries may use commands such as systemsetup -gettimezone or timeIntervalSinceNow to gather current time zone information or current date and time.
This information could be useful for performing other techniques, such as executing a file with a Scheduled Task/Job, or to discover locality information based on time zone to assist in victim targeting (i.e. System Location Discovery). Adversaries may also use knowledge of system time as part of a time bomb, or delaying execution until a specified date/time.
Rules on DetectionCode tagged with T1124.
| Rule | Level | Log source |
|---|---|---|
| Use of W32tm as Timer | high | windows / process_creation |
| Cisco Discovery | low | cisco / NULL |
| Discovery of a System Time | low | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows System Time Discovery W32tm Delay | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupBRONZE BUTLER | BRONZE BUTLER has used |
| GroupChimera | Chimera has used |
| GroupCURIUM | CURIUM deployed mechanisms to check system time information following strategic website compromise attacks. |
| GroupDarkhotel | Darkhotel malware can obtain system time from a compromised host. |
| GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`. |
| GroupHigaisa | Higaisa used a function to gather the current time. |
| GroupKimsuky | Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`. |
| GroupLazarus Group | A Destover-like implant used by Lazarus Group can obtain the current system time and send it to the C2 server. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla can collect the timestamp from the victim’s machine. |
| MalwareAppleSeed | AppleSeed can pull a timestamp from the victim's machine. |
| MalwareAstaroth | Astaroth collects the timestamp from the infected machine. |
| ToolAsyncRAT | AsyncRAT can check whether the current system hour and day of the week are within operating hours defined it its configuration. |
| MalwareAvosLocker | AvosLocker has checked the system time before and after encryption. |
| MalwareAzorult | Azorult can collect the time zone information from the system. |
| MalwareBADHATCH | BADHATCH can obtain the `DATETIME` and `UPTIME` from a compromised machine. |
| MalwareBazar | Bazar can collect the time on the compromised host. |
| Used by | Procedure example |
|---|---|
| CampaignC0015 | During C0015, the threat actors used the command `net view /all time` to gather the local time of a compromised network. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net time` command as part of their advanced reconnaissance. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used the `time` command to retrieve the current time of a compromised system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.