ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1016×

232 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareNGLite

NGLite identifies the victim system MAC and IPv4 addresses and uses these to establish a victim identifier.

T1016
System Network Configuration Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines.

T1016
System Network Configuration Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the domain of the compromised host.

T1016
System Network Configuration Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can gather the IP address from the victim's machine using the IP config command.

T1016
System Network Configuration Discovery
MalwareElise

Elise executes ipconfig /all after initial communication is made to the remote server.

T1016
System Network Configuration Discovery
MalwareUSBferry

USBferry can detect the infected machine's network topology using ipconfig and arp.

T1016
System Network Configuration Discovery
MalwareWannaCry

WannaCry will attempt to determine the local network segment it is a part of.

T1016
System Network Configuration Discovery
MalwareTSCookie

TSCookie has the ability to identify the IP of the infected host.

T1016
System Network Configuration Discovery
MalwareLatrodectus

Latrodectus can discover the IP and MAC address of a targeted host.

T1016
System Network Configuration Discovery
MalwareSaint Bot

Saint Bot can collect the IP address of a victim machine.

T1016
System Network Configuration Discovery
MalwarePay2Key

Pay2Key can identify the IP and MAC addresses of the compromised host.

T1016
System Network Configuration Discovery
MalwareLODEINFO

LODEINFO can enumerate the MAC address of the compromised host.

T1016
System Network Configuration Discovery
MalwareCharmPower

CharmPower has the ability to use ipconfig to enumerate system network settings.

T1016
System Network Configuration Discovery
MalwareQUADAGENT

QUADAGENT gathers the current domain the victim system belongs to.

T1016
System Network Configuration Discovery
MalwareSagerunex

Sagerunex will gather system information such as MAC and IP addresses.

T1016
System Network Configuration Discovery
MalwareSys10

Sys10 collects the local IP address of the victim and sends it to the C2.

T1016
System Network Configuration Discovery
MalwareRoyal

Royal can enumerate IP addresses using `GetIpAddrTable`.

T1016
System Network Configuration Discovery
MalwareTrojan.Karagany

Trojan.Karagany can gather information on the network configuration of a compromised host.

T1016
System Network Configuration Discovery
MalwareBandook

Bandook has a command to get the public IP address from a system.

T1016
System Network Configuration Discovery
MalwarePipeMon

PipeMon can collect and send the local IP address, RDP information, and the network adapter physical address as a part of its C2 beacon.

T1016
System Network Configuration Discovery
MalwareMagicRAT

MagicRAT collects system network information using commands such as `ipconfig /all`.

T1016
System Network Configuration Discovery
MalwareKONNI

KONNI can collect the IP address from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareT9000

T9000 gathers and beacons the MAC and IP addresses during installation.

T1016
System Network Configuration Discovery
MalwareShamoon

Shamoon obtains the target's IP address and local network segment.

T1016
System Network Configuration Discovery
MalwareJHUHUGIT

A JHUHUGIT variant gathers network interface card information.

T1016
System Network Configuration Discovery
MalwareBLUELIGHT

BLUELIGHT can collect IP information from the victim’s machine.

T1016
System Network Configuration Discovery
Malwaredown_new

down_new has the ability to identify the MAC address of a compromised host.

T1016
System Network Configuration Discovery
MalwareIxeshe

Ixeshe enumerates the IP address, network proxy settings, and domain name from a victim's system.

T1016
System Network Configuration Discovery
MalwareRedLine Stealer

RedLine Stealer can enumeate information about victims’ systems including IP addresses.

T1016
System Network Configuration Discovery
MalwareCatchamas

Catchamas gathers the Mac address, IP address, and the network adapter information from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareRogueRobin

RogueRobin gathers the IP address and domain from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareBoxCaon

BoxCaon can collect the victim's MAC address by using the GetAdaptersInfo API.

T1016
System Network Configuration Discovery
MalwareSDBbot

SDBbot has the ability to determine the domain name and whether a proxy is configured on a compromised host.

T1016
System Network Configuration Discovery
MalwareMosquito

Mosquito uses the ipconfig command.

T1016
System Network Configuration Discovery
MalwareQUIETCANARY

QUIETCANARY can identify the default proxy setting on a compromised host.

T1016
System Network Configuration Discovery
MalwareGrandoreiro

Grandoreiro can determine the IP and physical location of the compromised host via IPinfo.

T1016
System Network Configuration Discovery
MalwareWellMail

WellMail can identify the IP address of the victim system.

T1016
System Network Configuration Discovery
MalwareLiteDuke

LiteDuke has the ability to discover the proxy configuration of Firefox and/or Opera.

T1016
System Network Configuration Discovery
MalwareSibot

Sibot checked if the compromised system is configured to use proxies.

T1016
System Network Configuration Discovery
MalwareBazar

Bazar can collect the IP address and NetBIOS name of an infected machine.

T1016
System Network Configuration Discovery
MalwareKobalos

Kobalos can record the IP address of the target machine.

T1016
System Network Configuration Discovery
MalwareRATANKBA

RATANKBA gathers the victim’s IP address via the ipconfig -all command.

T1016
System Network Configuration Discovery
MalwareBADCALL

BADCALL collects the network adapter information.

T1016
System Network Configuration Discovery
MalwareMoonWind

MoonWind obtains the victim IP address.

T1016
System Network Configuration Discovery
MalwareRyuk

Ryuk has called GetIpNetTable in attempt to identify all mounted drives and hosts that have Address Resolution Protocol (ARP) entries.

T1016
System Network Configuration Discovery
MalwarePysa

Pysa can perform network reconnaissance using the Advanced IP Scanner tool.

T1016
System Network Configuration Discovery
MalwareZebrocy

Zebrocy runs the ipconfig /all command.

T1016
System Network Configuration Discovery
MalwareSpeakUp

SpeakUp uses the ifconfig -a command.

T1016
System Network Configuration Discovery
MalwareCobalt Strike

Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers.

T1016
System Network Configuration Discovery
MalwareSUNBURST

SUNBURST collected all network interface MAC addresses that are up and not loopback devices, as well as IP address, DHCP configuration, and domain information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.