ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1016×

232 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareHotCroissant

HotCroissant has the ability to identify the IP address of the compromised machine.

T1016
System Network Configuration Discovery
MalwareUnknown Logger

Unknown Logger can obtain information about the victim's IP address.

T1016
System Network Configuration Discovery
MalwareValak

Valak has the ability to identify the domain and the MAC and IP addresses of an infected machine.

T1016
System Network Configuration Discovery
MalwareMilan

Milan can run `C:\Windows\system32\cmd.exe /c cmd /c ipconfig /all 2>&1` to discover network settings.

T1016
System Network Configuration Discovery
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host.

T1016
System Network Configuration Discovery
MalwareTaidoor

Taidoor has collected the MAC address of a compromised host; it can also use GetAdaptersInfo to identify network adapters.

T1016
System Network Configuration Discovery
MalwareCyclops Blink

Cyclops Blink can use the Linux API `if_nameindex` to gather network interface names.

T1016
System Network Configuration Discovery
MalwareNanoCore

NanoCore gathers the IP address from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareTajMahal

TajMahal has the ability to identify the MAC address on an infected host.

T1016
System Network Configuration Discovery
MalwareCarbon

Carbon can collect the IP address of the victims and other computers on the network using the commands: ipconfig -all nbtstat -n, and nbtstat -s.

T1016
System Network Configuration Discovery
MalwareCalisto

Calisto runs the ifconfig command to obtain the IP address from the victim’s machine.

T1016
System Network Configuration Discovery
MalwarePisloader

Pisloader has a command to collect the victim's IP address.

T1016
System Network Configuration Discovery
MalwareRamsay

Ramsay can use ipconfig and Arp to collect network configuration information, including routing information and ARP tables.

T1016
System Network Configuration Discovery
MalwareRevenge RAT

Revenge RAT collects the IP address and MAC address from the system.

T1016
System Network Configuration Discovery
MalwareMacMa

MacMa can collect IP addresses from a compromised host.

T1016
System Network Configuration Discovery
MalwareFunnyDream

FunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies.

T1016
System Network Configuration Discovery
MalwareMore_eggs

More_eggs has the capability to gather the IP address from the victim's machine.

T1016
System Network Configuration Discovery
MalwareSysUpdate

SysUpdate can collected the IP address and domain name of a compromised host.

T1016
System Network Configuration Discovery
MalwareKwampirs

Kwampirs collects network adapter and interface information by using the commands ipconfig /all, arp -a and route print. It also collects the system's MAC address with getmac and domain configuration with net config workstation.

T1016
System Network Configuration Discovery
MalwareDEADEYE

DEADEYE can discover the DNS domain name of a targeted system.

T1016
System Network Configuration Discovery
MalwareLAMEHUG

LAMEHUG can enumerate network information on compromised hosts.

T1016
System Network Configuration Discovery
MalwareKessel

Kessel has collected the DNS address of the infected host.

T1016
System Network Configuration Discovery
MalwareGrimAgent

GrimAgent can enumerate the IP and domain of a target system.

T1016
System Network Configuration Discovery
MalwareLokibot

Lokibot has the ability to discover the domain name of the infected host.

T1016
System Network Configuration Discovery
MalwareFELIXROOT

FELIXROOT collects information about the network including the IP address and DHCP server.

T1016
System Network Configuration Discovery
MalwarePenquin

Penquin can report the IP of the compromised host to attacker controlled infrastructure.

T1016
System Network Configuration Discovery
MalwareBabyShark

BabyShark has executed the ipconfig /all command.

T1016
System Network Configuration Discovery
MalwareCreepySnail

CreepySnail can use `getmac` and `Get-NetIPAddress` to enumerate network settings.

T1016
System Network Configuration Discovery
MalwareTroll Stealer

Troll Stealer collects the MAC address of victim devices.

T1016
System Network Configuration Discovery
MalwareManjusaka

Manjusaka gathers information about current network connections, local and remote addresses associated with them, and associated processes.

T1016
System Network Configuration Discovery
MalwareIceApple

The IceApple ifconfig module can iterate over all network interfaces on the host and retrieve the name, description, MAC address, DNS suffix, DNS servers, gateways, IPv4 addresses, and subnet masks.

T1016
System Network Configuration Discovery
MalwareJPIN

JPIN can obtain network information, including DNS, IP, and proxies.

T1016
System Network Configuration Discovery
MalwareSideTwist

SideTwist has the ability to collect the domain name on a compromised host.

T1016
System Network Configuration Discovery
MalwareMis-Type

Mis-Type may create a file containing the results of the command cmd.exe /c ipconfig /all.

T1016
System Network Configuration Discovery
MalwareLunarWeb

LunarWeb can use shell commands to discover network adapters and configuration.

T1016
System Network Configuration Discovery
MalwareOctopus

Octopus can collect the host IP address from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareQilin

Qilin can accept a command line argument identifying specific IPs.

T1016
System Network Configuration Discovery
MalwareSoreFang

SoreFang can collect the TCP/IP, DNS, DHCP, and network adapter configuration on a compromised host via ipconfig.exe /all.

T1016
System Network Configuration Discovery
MalwareSTARWHALE

STARWHALE has the ability to collect the IP address of an infected host.

T1016
System Network Configuration Discovery
MalwareIndustroyer

Industroyer’s 61850 payload component enumerates connected network adapters and their corresponding IP addresses.

T1016
System Network Configuration Discovery
MalwareKevin

Kevin can collect the MAC address and other information from a victim machine using `ipconfig/all`.

T1016
System Network Configuration Discovery
MalwareAgent Tesla

Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings.

T1016
System Network Configuration Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts.

T1016
System Network Configuration Discovery
MalwareShadowPad

ShadowPad has collected the domain name of the victim system.

T1016
System Network Configuration Discovery
MalwareAstaroth

Astaroth collects the external IP address from the system.

T1016
System Network Configuration Discovery
MalwareQakBot

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.

T1016
System Network Configuration Discovery
MalwarejRAT

jRAT can gather victim internal and external IPs.

T1016
System Network Configuration Discovery
MalwareDenis

Denis uses ipconfig to gather the IP address from the system.

T1016
System Network Configuration Discovery
MalwareComnie

Comnie uses ipconfig /all and route PRINT to identify network adapter and interface information.

T1016
System Network Configuration Discovery
MalwareOSInfo

OSInfo discovers the current domain information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.