Real-world descriptions of how a group, tool or campaign used a technique.
83 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1124 System Time Discovery |
MalwareRTM | RTM can obtain the victim time zone. |
| T1124 System Time Discovery |
MalwareGrandoreiro | Grandoreiro can determine the time on the victim machine via IPinfo. |
| T1124 System Time Discovery |
MalwareBazar | Bazar can collect the time on the compromised host. |
| T1124 System Time Discovery |
MalwareMoonWind | MoonWind obtains the victim's current time. |
| T1124 System Time Discovery |
Malwareccf32 | ccf32 can determine the local time on targeted machines. |
| T1124 System Time Discovery |
MalwareZebrocy | Zebrocy gathers the current time zone and date information from the system. |
| T1124 System Time Discovery |
MalwareSUNBURST | SUNBURST collected device `UPTIME`. |
| T1124 System Time Discovery |
MalwareEvilBunny | EvilBunny has used the API calls NtQuerySystemTime, GetSystemTimeAsFileTime, and GetTickCount to gather time metrics as part of its checks to see if the malware is running in a sandbox. |
| T1124 System Time Discovery |
MalwareTaidoor | Taidoor can use |
| T1124 System Time Discovery |
MalwareTajMahal | TajMahal has the ability to determine local time on a compromised host. |
| T1124 System Time Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers victim machine timezone information. |
| T1124 System Time Discovery |
MalwareCarbon | Carbon uses the command |
| T1124 System Time Discovery |
MalwareBISCUIT | BISCUIT has a command to collect the system `UPTIME`. |
| T1124 System Time Discovery |
MalwareFunnyDream | FunnyDream can check system time to help determine when changes were made to specified files. |
| T1124 System Time Discovery |
MalwareEgregor | Egregor contains functionality to query the local/system time. |
| T1124 System Time Discovery |
MalwareFELIXROOT | FELIXROOT gathers the time zone information from the victim’s machine. |
| T1124 System Time Discovery |
MalwareCannon | Cannon can collect the current time zone information from the victim’s machine. |
| T1124 System Time Discovery |
Malwarebuild_downer | build_downer has the ability to determine the local time to ensure malware installation only happens during the hours that the infected system is active. |
| T1124 System Time Discovery |
MalwareComRAT | ComRAT has checked the victim system's date and time to perform tasks during business hours (9 to 5, Monday to Friday). |
| T1124 System Time Discovery |
MalwareAgent Tesla | Agent Tesla can collect the timestamp from the victim’s machine. |
| T1124 System Time Discovery |
MalwareStarProxy | StarProxy has utilized the windows API call `GetLocalTime()` to retrieve a SystemTime structure to generate a seed value. |
| T1124 System Time Discovery |
MalwareShadowPad | ShadowPad has collected the current date and time of the victim system. |
| T1124 System Time Discovery |
MalwareAstaroth | Astaroth collects the timestamp from the infected machine. |
| T1124 System Time Discovery |
MalwareQakBot | QakBot can identify the system time on a targeted host. |
| T1124 System Time Discovery |
MalwareDEADWOOD | DEADWOOD will set a timestamp value to determine when wiping functionality starts. When the timestamp is met on the system, a trigger file is created on the operating system allowing for execution to proceed. If the timestamp is in the past, the wiper will execute immediately. |
| T1124 System Time Discovery |
MalwareAzorult | Azorult can collect the time zone information from the system. |
| T1124 System Time Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to obtain the time zone information and the current timestamp of the victim’s machine. |
| T1124 System Time Discovery |
MalwareStrifeWater | StrifeWater can collect the time zone from the victim's machine. |
| T1124 System Time Discovery |
ToolNet | The |
| T1124 System Time Discovery |
ToolSILENTTRINITY | SILENTTRINITY can collect start time information from a compromised host. |
| T1124 System Time Discovery |
ToolAsyncRAT | AsyncRAT can check whether the current system hour and day of the week are within operating hours defined it its configuration. |
| T1124 System Time Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has queried the system timezone configuration and timezone data files to include `/etc/localtime`, and locale settings to determine the geolocation of the compromised host. |
| T1124 System Time Discovery |
MalwareCanisterWorm | CanisterWorm has checked if the target system’s time zone is “Asia/Tehran” or “Iran.” |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.