T1016 System Network Configuration Discovery in real malware
ATT&CK technique T1016 System Network Configuration Discovery appears in 16 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: Philis, Jqxm, Brontok, Gavir, HUILoader.
Tactics: discovery
Prevalence in the corpus
- Samples exhibiting T1016: 16
- Share of analyzed corpus: 0.0%
- Last 7 days: 0 · prior 7 days: 0 (flat)
Malware families using T1016
Example samples
- fa8b85ee420225d7b5eb38340e9cd9622c632465dc8e12c8601cd55c55e485c2 - malicious
- 1faf77591670aceef43e14dc007363212e53f07cc6a19053e4b4c5f162d9c5c6 - malicious
- 4daaa8c721d73c4e924ef31e2c9d17eb164e28c583b78cd291e9463bac26bcdd - malicious
- 1e447bd1dc992ba893df8b40e2f4d50fae71ec5db144f88115b16129f16d10fa - malicious
- a83532d8494537d8facd84bc64a84b98d92020aae05e681d3b18459c5e12cc7c - malicious
- 6be615706523d4dfe5092625728759f303866869b09e4af4f73b126e6737ce7c - malicious
- 0e61e8e6d4118a5b4a3a11fdf887fd2f504be8468c56dd5601c5d41fb5e845eb - malicious
- 75c4153b0b885146ef3cbfcd92293efa7b7b9cf58338663e4018c08cb0bd1282 - malicious
- 46b4995654c4fb5f1be2a865481392ca98c1a794b445b0dbd3734182e933b488 - malicious
- 831b1446bb39d3fa83fc16dca17a9b48e1851a4aedc61e9e14289e5114994a6f - malicious
- virussign.com_981ee0db7b5c8134d67da3d9c47afa60.vir - malicious
- 0d63fc3810249afea97d64d6e99764eae41acbe537ee26d505626344c78c93dc.exe - malicious
- 083810fec4a8c6511c358fd5875df6a2f687c797346c56f0a9d415fcc9e3bb2e.exe - malicious
- 05c3b47afb380b13f107d9cef1ec168c24d5f1e16d7179965f89937280825823.exe - malicious
- 1c87fe28e8c3b34b6188aa2f079afb11e02c94584a7e2b42757ceadb67a7d584.exe - malicious
- 076cd8f9c0a81780810f5708c8f5ce0e7d3dc38bf9ec339746a1eb400655d0f3.exe - malicious
Canonical technique definition: MITRE ATT&CK T1016 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1016
- How common is ATT&CK T1016 (System Network Configuration Discovery) in real malware?
- ATT&CK technique T1016 System Network Configuration Discovery appears in 16 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: Philis, Jqxm, Brontok, Gavir, HUILoader.
- Which malware families use T1016?
- In this corpus T1016 is most associated with Philis (4), Jqxm (3), Brontok (1), Gavir (1), HUILoader (1). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1016?
- 0.0% of the publicly analyzed corpus (16 of 114611 samples) exhibits T1016. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats