ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1614×

25 examples

TechniqueUsed byProcedure example
T1614
System Location Discovery
MalwareAmadey

Amadey does not run any tasks or install additional malware if the victim machine is based in Russia.

T1614
System Location Discovery
MalwareTsundere Botnet

Tsundere Botnet has checked the victim machine’s location by obtaining the culture name of the machine.

T1614
System Location Discovery
MalwareInvisibleFerret

InvisibleFerret has collected the internal IP address, IP geolocation information of the infected host and sends the data to a C2 server. InvisibleFerret has also leveraged the “pay” module to obtain region name, country, city, zip code, ISP, latitude and longitude using “http://ip-api.com/json”.

T1614
System Location Discovery
MalwareCrimson

Crimson can identify the geographical location of a victim host.

T1614
System Location Discovery
MalwareGootloader

Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea.

T1614
System Location Discovery
MalwareHexEval Loader

HexEval Loader has a function where the C2 endpoint can identify the geographical location of a victim host based on request headers, execution environment and runtime conditions.

T1614
System Location Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can determine the geographical location of a victim host by checking the language.

T1614
System Location Discovery
MalwareSameCoin

SameCoin can attempt to connect to the Israel Home Front Command site, oref.org[.]il, which is only reachable from within Israel to verify the target's location.

T1614
System Location Discovery
MalwareRagnar Locker

Before executing malicious code, Ragnar Locker checks the Windows API GetLocaleInfoW and doesn't encrypt files if it finds a former Soviet country.

T1614
System Location Discovery
MalwareSocGholish

SocGholish can use IP-based geolocation to limit infections to victims in North America, Europe, and a small number of Asian-Pacific nations.

T1614
System Location Discovery
MalwareDarkWatchman

DarkWatchman can identity the OS locale of a compromised host.

T1614
System Location Discovery
MalwarePlugX

PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`.

T1614
System Location Discovery
MalwarePureCrypter

PureCrypter can use `kernel32!GetGeoInfo` to determine system location.

T1614
System Location Discovery
MalwareDarkGate

DarkGate queries system locale information during execution. Later versions of DarkGate query GetSystemDefaultLCID for locale information to determine if the malware is executing in Russian-speaking countries.

T1614
System Location Discovery
MalwareSaint Bot

Saint Bot has conducted system locale checks to see if the compromised host is in Russia, Ukraine, Belarus, Armenia, Kazakhstan, or Moldova.

T1614
System Location Discovery
MalwareGlassWorm

GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute.

T1614
System Location Discovery
MalwareRedLine Stealer

RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service.

T1614
System Location Discovery
MalwareSDBbot

SDBbot can collected the country code of a compromised machine.

T1614
System Location Discovery
MalwareRaccoon Stealer

Raccoon Stealer collects the `Locale Name` of the infected device via `GetUserDefaultLocaleName` to determine whether the string `ru` is included, but in analyzed samples no action is taken if present.

T1614
System Location Discovery
MalwareAshTag

AshTag can check geolocation on targeted systems.

T1614
System Location Discovery
MalwareGrimAgent

GrimAgent can identify the country code on a compromised host.

T1614
System Location Discovery
MalwareXORIndex Loader

XORIndex Loader can identify the geographical location of a victim host.

T1614
System Location Discovery
ToolRemcos

Remcos can identify the location of targeted devices.

T1614
System Location Discovery
ToolQuasarRAT

QuasarRAT can determine the country a victim host is located in.

T1614
System Location Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has discovered the compromised systems location through a query of the system timezone configuration and the locale settings.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.