T1033 System Owner/User Discovery in real malware
ATT&CK technique T1033 System Owner/User Discovery appears in 11 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is rising (6 recent vs 0 prior). Most associated families: Jqxm, Philis, Brontok, HUILoader.
Tactics: discovery
Prevalence in the corpus
- Samples exhibiting T1033: 11
- Share of analyzed corpus: 0.0%
- Last 7 days: 6 · prior 7 days: 0 (rising)
Malware families using T1033
Example samples
- 6be615706523d4dfe5092625728759f303866869b09e4af4f73b126e6737ce7c - malicious
- 0e61e8e6d4118a5b4a3a11fdf887fd2f504be8468c56dd5601c5d41fb5e845eb - malicious
- 75c4153b0b885146ef3cbfcd92293efa7b7b9cf58338663e4018c08cb0bd1282 - malicious
- 46b4995654c4fb5f1be2a865481392ca98c1a794b445b0dbd3734182e933b488 - malicious
- 831b1446bb39d3fa83fc16dca17a9b48e1851a4aedc61e9e14289e5114994a6f - malicious
- virussign.com_981ee0db7b5c8134d67da3d9c47afa60.vir - malicious
- 0d63fc3810249afea97d64d6e99764eae41acbe537ee26d505626344c78c93dc.exe - malicious
- 083810fec4a8c6511c358fd5875df6a2f687c797346c56f0a9d415fcc9e3bb2e.exe - malicious
- 05c3b47afb380b13f107d9cef1ec168c24d5f1e16d7179965f89937280825823.exe - malicious
- 1c87fe28e8c3b34b6188aa2f079afb11e02c94584a7e2b42757ceadb67a7d584.exe - malicious
- 076cd8f9c0a81780810f5708c8f5ce0e7d3dc38bf9ec339746a1eb400655d0f3.exe - malicious
Canonical technique definition: MITRE ATT&CK T1033 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1033
- How common is ATT&CK T1033 (System Owner/User Discovery) in real malware?
- ATT&CK technique T1033 System Owner/User Discovery appears in 11 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is rising (6 recent vs 0 prior). Most associated families: Jqxm, Philis, Brontok, HUILoader.
- Is T1033 becoming more common?
- Prevalence is rising: 6 samples in the last seven days against 0 in the seven days before. This measures submissions to MalwareAnalyzer by Cyble, so it reflects what is being submitted here rather than global attacker behaviour.
- Which malware families use T1033?
- In this corpus T1033 is most associated with Jqxm (2), Philis (2), Brontok (1), HUILoader (1). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1033?
- 0.0% of the publicly analyzed corpus (11 of 100981 samples) exhibits T1033. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats