ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareBOLDMOVE

BOLDMOVE enumerates network interfaces on the infected host.

T1016
System Network Configuration Discovery
MalwareCrimson

Crimson contains a command to collect the victim MAC address and LAN IP.

T1016
System Network Configuration Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate infected system network information.

T1016
System Network Configuration Discovery
MalwareTurian

Turian can retrieve the internal IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareMachete

Machete collects the MAC address of the target computer and other network configuration information.

T1016
System Network Configuration Discovery
MalwareAction RAT

Action RAT has the ability to collect the MAC address of an infected host.

T1016
System Network Configuration Discovery
MalwareAvenger

Avenger can identify the domain of the compromised host.

T1016
System Network Configuration Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about its IP addresses and MAC addresses.

T1016
System Network Configuration Discovery
MalwarePUBLOAD

PUBLOAD has obtained information about local networks through the `ipconfig /all` command.

T1016
System Network Configuration Discovery
MalwareGootloader

Gootloader can use an embedded script to check the IP address of potential victims visiting compromised websites.

T1016
System Network Configuration Discovery
MalwarePingPull

PingPull can retrieve the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareWellMess

WellMess can identify the IP address and user domain on the target machine.

T1016
System Network Configuration Discovery
MalwareWoody RAT

Woody RAT can retrieve network interface and proxy information.

T1016
System Network Configuration Discovery
MalwareMafalda

Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table.

T1016
System Network Configuration Discovery
MalwareSquirrelwaffle

Squirrelwaffle has collected the victim’s external IP address.

T1016
System Network Configuration Discovery
MalwareHexEval Loader

HexEval Loader has leveraged server-side client configurations to identify the public IP of the victim host.

T1016
System Network Configuration Discovery
MalwareShrinkLocker

ShrinkLocker captures the IP address of the victim system and sends this to the attacker following encryption.

T1016
System Network Configuration Discovery
MalwareAgent.btz

Agent.btz collects the network adapter’s IP and MAC address as well as IP addresses of the network adapter’s default gateway, primary/secondary WINS, DHCP, and DNS servers, and saves them into a log file.

T1016
System Network Configuration Discovery
MalwareRifdoor

Rifdoor has the ability to identify the IP address of the compromised host.

T1016
System Network Configuration Discovery
MalwareInvisiMole

InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID.

T1016
System Network Configuration Discovery
MalwareNaid

Naid collects the domain name from a compromised host.

T1016
System Network Configuration Discovery
MalwareVolgmer

Volgmer can gather the IP address from the victim's machine.

T1016
System Network Configuration Discovery
MalwareZeroT

ZeroT gathers the victim's IP address and domain information, and then sends it to its C2 server.

T1016
System Network Configuration Discovery
MalwareOkrum

Okrum can collect network information, including the host IP address, DNS, and proxy information.

T1016
System Network Configuration Discovery
MalwareBonadan

Bonadan can find the external IP address of the infected host.

T1016
System Network Configuration Discovery
MalwareNeoichor

Neoichor can gather the IP address from an infected host.

T1016
System Network Configuration Discovery
MalwareConti

Conti can retrieve the ARP cache from the local system by using the GetIpNetTable() API call and check to ensure IP addresses it connects to are for local, non-Internet, systems.

T1016
System Network Configuration Discovery
MalwareDiavol

Diavol can enumerate victims' local and external IPs when registering with C2.

T1016
System Network Configuration Discovery
MalwareIcedID

IcedID used the `ipconfig /all` command and a batch script to gather network information.

T1016
System Network Configuration Discovery
MalwareVERMIN

VERMIN gathers the local IP address.

T1016
System Network Configuration Discovery
MalwareNightdoor

Nightdoor gathers information on victim system network configuration such as MAC addresses.

T1016
System Network Configuration Discovery
MalwarePowerShower

PowerShower has the ability to identify the current Windows domain of the infected host.

T1016
System Network Configuration Discovery
MalwareKazuar

Kazuar gathers information about network adapters.

T1016
System Network Configuration Discovery
MalwareFatDuke

FatDuke can identify the MAC address on the target computer.

T1016
System Network Configuration Discovery
MalwareLucifer

Lucifer can collect the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareBlackEnergy

BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe.

T1016
System Network Configuration Discovery
MalwarezwShell

zwShell can obtain the victim IP address.

T1016
System Network Configuration Discovery
MalwareRising Sun

Rising Sun can detect network adapter and IP address information.

T1016
System Network Configuration Discovery
MalwareChrommme

Chrommme can enumerate the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareAvaddon

Avaddon can collect the external IP address of the victim.

T1016
System Network Configuration Discovery
MalwareSocGholish

SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain.

T1016
System Network Configuration Discovery
MalwareFlagpro

Flagpro has been used to execute the ipconfig /all command on a victim system.

T1016
System Network Configuration Discovery
MalwareSpicyOmelette

SpicyOmelette can identify the IP of a compromised system.

T1016
System Network Configuration Discovery
MalwareGreen Lambert

Green Lambert can obtain proxy information from a victim's machine using system environment variables.

T1016
System Network Configuration Discovery
MalwareGoldMax

GoldMax retrieved a list of the system's network interface after execution.

T1016
System Network Configuration Discovery
MalwareKeyBoy

KeyBoy can determine the public or WAN IP address for the system.

T1016
System Network Configuration Discovery
MalwareAnchor

Anchor can determine the public IP and location of a compromised host.

T1016
System Network Configuration Discovery
MalwareDyre

Dyre has the ability to identify network settings on a compromised host.

T1016
System Network Configuration Discovery
MalwareLunarLoader

LunarLoader can verify the targeted host's DNS name which is then used in the creation of a decyrption key.

T1016
System Network Configuration Discovery
MalwarePlugX

PlugX has captured victim IP address details of the targeted machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.