ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1016.001×

13 examples

TechniqueUsed byProcedure example
T1016.001
Internet Connection Discovery
MalwareQuietSieve

QuietSieve can check C2 connectivity with a `ping` to 8.8.8.8 (Google public DNS).

T1016.001
Internet Connection Discovery
MalwareHavoc

The Havoc demon can check for a connection to the C2 server from the target machine.

T1016.001
Internet Connection Discovery
MalwarePUBLOAD

PUBLOAD has identified internet connectivity details through commands such as `tracert -h 5 -4 google.com` and `curl http://myip.ipip.net`.

T1016.001
Internet Connection Discovery
MalwareWoody RAT

Woody RAT can make `Ping` GET HTTP requests to its C2 server at regular intervals for network connectivity checks.

T1016.001
Internet Connection Discovery
MalwareSUGARUSH

SUGARUSH has checked for internet connectivity from an infected host before attempting to establish a new TCP connection.

T1016.001
Internet Connection Discovery
MalwareNeoichor

Neoichor can check for Internet connectivity by contacting bing[.]com with the request format `bing[.]com?id=<GetTickCount>`.

T1016.001
Internet Connection Discovery
MalwareRising Sun

Rising Sun can test a connection to a specified network IP address over a specified port number.

T1016.001
Internet Connection Discovery
MalwareDarkTortilla

DarkTortilla can check for internet connectivity by issuing HTTP GET requests.

T1016.001
Internet Connection Discovery
MalwareGoldFinder

GoldFinder performed HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request traveled through.

T1016.001
Internet Connection Discovery
MalwareNKAbuse

NKAbuse utilizes external services such as ifconfig.me to identify the victim machine's IP address.

T1016.001
Internet Connection Discovery
MalwareMore_eggs

More_eggs has used HTTP GET requests to check internet connectivity.

T1016.001
Internet Connection Discovery
MalwareSysUpdate

SysUpdate can contact the DNS server operated by Google as part of its C2 establishment process.

T1016.001
Internet Connection Discovery
MalwareQakBot

QakBot can measure the download speed on a targeted host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.