ATT&CKReferencesGovCERT Carbon May 2016

GovCERT Carbon May 2016

GovCERT. (2016, May 23). Technical Report about the Espionage Case at RUAG. Retrieved November 7, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareCarbon

Carbon can collect the IP address of the victims and other computers on the network using the commands: ipconfig -all nbtstat -n, and nbtstat -s.

T1018
Remote System Discovery
MalwareCarbon

Carbon uses the net view command.

T1049
System Network Connections Discovery
MalwareCarbon

Carbon uses the netstat -r and netstat -an commands.

T1069
Permission Groups Discovery
MalwareCarbon

Carbon uses the net group command.

T1124
System Time Discovery
MalwareCarbon

Carbon uses the command net time \\127.0.0.1 to get information the system’s time.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.