ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1124×

83 examples

TechniqueUsed byProcedure example
T1124
System Time Discovery
MalwareRTM

RTM can obtain the victim time zone.

T1124
System Time Discovery
MalwareGrandoreiro

Grandoreiro can determine the time on the victim machine via IPinfo.

T1124
System Time Discovery
MalwareBazar

Bazar can collect the time on the compromised host.

T1124
System Time Discovery
MalwareMoonWind

MoonWind obtains the victim's current time.

T1124
System Time Discovery
Malwareccf32

ccf32 can determine the local time on targeted machines.

T1124
System Time Discovery
MalwareZebrocy

Zebrocy gathers the current time zone and date information from the system.

T1124
System Time Discovery
MalwareSUNBURST

SUNBURST collected device `UPTIME`.

T1124
System Time Discovery
MalwareEvilBunny

EvilBunny has used the API calls NtQuerySystemTime, GetSystemTimeAsFileTime, and GetTickCount to gather time metrics as part of its checks to see if the malware is running in a sandbox.

T1124
System Time Discovery
MalwareTaidoor

Taidoor can use GetLocalTime and GetSystemTime to collect system time.

T1124
System Time Discovery
MalwareTajMahal

TajMahal has the ability to determine local time on a compromised host.

T1124
System Time Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers victim machine timezone information.

T1124
System Time Discovery
MalwareCarbon

Carbon uses the command net time \\127.0.0.1 to get information the system’s time.

T1124
System Time Discovery
MalwareBISCUIT

BISCUIT has a command to collect the system `UPTIME`.

T1124
System Time Discovery
MalwareFunnyDream

FunnyDream can check system time to help determine when changes were made to specified files.

T1124
System Time Discovery
MalwareEgregor

Egregor contains functionality to query the local/system time.

T1124
System Time Discovery
MalwareFELIXROOT

FELIXROOT gathers the time zone information from the victim’s machine.

T1124
System Time Discovery
MalwareCannon

Cannon can collect the current time zone information from the victim’s machine.

T1124
System Time Discovery
Malwarebuild_downer

build_downer has the ability to determine the local time to ensure malware installation only happens during the hours that the infected system is active.

T1124
System Time Discovery
MalwareComRAT

ComRAT has checked the victim system's date and time to perform tasks during business hours (9 to 5, Monday to Friday).

T1124
System Time Discovery
MalwareAgent Tesla

Agent Tesla can collect the timestamp from the victim’s machine.

T1124
System Time Discovery
MalwareStarProxy

StarProxy has utilized the windows API call `GetLocalTime()` to retrieve a SystemTime structure to generate a seed value.

T1124
System Time Discovery
MalwareShadowPad

ShadowPad has collected the current date and time of the victim system.

T1124
System Time Discovery
MalwareAstaroth

Astaroth collects the timestamp from the infected machine.

T1124
System Time Discovery
MalwareQakBot

QakBot can identify the system time on a targeted host.

T1124
System Time Discovery
MalwareDEADWOOD

DEADWOOD will set a timestamp value to determine when wiping functionality starts. When the timestamp is met on the system, a trigger file is created on the operating system allowing for execution to proceed. If the timestamp is in the past, the wiper will execute immediately.

T1124
System Time Discovery
MalwareAzorult

Azorult can collect the time zone information from the system.

T1124
System Time Discovery
MalwareUPPERCUT

UPPERCUT has the capability to obtain the time zone information and the current timestamp of the victim’s machine.

T1124
System Time Discovery
MalwareStrifeWater

StrifeWater can collect the time zone from the victim's machine.

T1124
System Time Discovery
ToolNet

The net time command can be used in Net to determine the local or remote system time.

T1124
System Time Discovery
ToolSILENTTRINITY

SILENTTRINITY can collect start time information from a compromised host.

T1124
System Time Discovery
ToolAsyncRAT

AsyncRAT can check whether the current system hour and day of the week are within operating hours defined it its configuration.

T1124
System Time Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has queried the system timezone configuration and timezone data files to include `/etc/localtime`, and locale settings to determine the geolocation of the compromised host.

T1124
System Time Discovery
MalwareCanisterWorm

CanisterWorm has checked if the target system’s time zone is “Asia/Tehran” or “Iran.”

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.