Internet Connection Discovery

T1016.001

Sub-technique of T1016 System Network Configuration Discovery.View on attack.mitre.org

About this technique

Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in numerous ways such as using Ping, tracert, and GET requests to websites, or performing initial speed testing to confirm bandwidth.

Adversaries may use the results and responses from these requests to determine if the system is capable of communicating with their C2 servers before attempting to connect to them. The results may also be used to identify routes, redirectors, and proxy servers.

Detection rules1

Rules on DetectionCode tagged with T1016.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
Network Discovery Using Route Windows AppHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups11

Software13

Campaigns2

Procedure examples26

Groups11

Used byProcedure example
GroupAPT29

APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it.

GroupFIN13

FIN13 has used `Ping` and `tracert` for network reconnaissance efforts.

GroupFIN8

FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers.

GroupGamaredon Group

Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status.

GroupHAFNIUM

HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`.

GroupHEXANE

HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts.

GroupLotus Blossom

Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet.

GroupMagic Hound

Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity.

View all 11 groups examples

Software13

Used byProcedure example
MalwareDarkTortilla

DarkTortilla can check for internet connectivity by issuing HTTP GET requests.

MalwareGoldFinder

GoldFinder performed HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request traveled through.

MalwareHavoc

The Havoc demon can check for a connection to the C2 server from the target machine.

MalwareMore_eggs

More_eggs has used HTTP GET requests to check internet connectivity.

MalwareNeoichor

Neoichor can check for Internet connectivity by contacting bing[.]com with the request format `bing[.]com?id=<GetTickCount>`.

MalwareNKAbuse

NKAbuse utilizes external services such as ifconfig.me to identify the victim machine's IP address.

MalwarePUBLOAD

PUBLOAD has identified internet connectivity details through commands such as `tracert -h 5 -4 google.com` and `curl http://myip.ipip.net`.

MalwareQakBot

QakBot can measure the download speed on a targeted host.

View all 13 software examples

Campaigns2

Used byProcedure example
CampaignOperation Wocao

During Operation Wocao, threat actors used a Visual Basic script that checked for internet connectivity.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.