ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1497.001×

61 examples

TechniqueUsed byProcedure example
T1497.001
System Checks
MalwarePikabot

Pikabot performs a variety of system checks to determine if it is running in an analysis environment or sandbox, such as checking the number of processors (must be greater than two), and the amount of RAM (must be greater than 2GB).

T1497.001
System Checks
MalwareSynAck

SynAck checks its directory location in an attempt to avoid launching in a sandbox.

T1497.001
System Checks
MalwareBumblebee

Bumblebee has the ability to search for designated file paths and Registry keys that indicate a virtualized environment from multiple products.

T1497.001
System Checks
Malwareyty

yty has some basic anti-sandbox detection that tries to detect Virtual PC, Sandboxie, and VMware.

T1497.001
System Checks
MalwareSmoke Loader

Smoke Loader scans processes to perform anti-VM checks.

T1497.001
System Checks
MalwareHeartCrypt

HeartCrypt will attempt to load non-existent DLLs in attempt to detect sandbox creation of a dummy DLL to prevent the program from crashing.

T1497.001
System Checks
MalwareGravityRAT

GravityRAT uses WMI to check the BIOS and manufacturer information for strings like "VMWare", "Virtual", and "XEN" and another WMI request to get the current temperature of the hardware to determine if it's a virtual machine environment.

T1497.001
System Checks
MalwaremacOS.OSAMiner

macOS.OSAMiner can parse the output of the native `system_profiler` tool to determine if the machine is running with 4 cores.

T1497.001
System Checks
MalwareDUSTTRAP

DUSTTRAP decryption relies on the infected machine's `HKLM\SOFTWARE\Microsoft\Cryptography\MachineGUID` value.

T1497.001
System Checks
MalwareSnip3

Snip3 has the ability to detect Windows Sandbox, VMWare, or VirtualBox by querying `Win32_ComputerSystem` to extract the `Manufacturer` string.

T1497.001
System Checks
MalwareGuLoader

GuLoader has the ability to perform anti-VM and anti-sandbox checks using string hashing, the API call EnumWindows, and checking for Qemu guest agent.

T1497.001
System Checks
MalwareWastedLocker

WastedLocker checked if UCOMIEnumConnections and IActiveScriptParseProcedure32 Registry keys were detected as part of its anti-analysis technique.

T1497.001
System Checks
MalwareInvisiMole

InvisiMole can check for artifacts of VirtualBox, Virtual PC and VMware environment, and terminate itself if they are detected.

T1497.001
System Checks
MalwareWhisperGate

WhisperGate can stop its execution when it recognizes the presence of certain monitoring tools.

T1497.001
System Checks
MalwareOkrum

Okrum's loader can check the amount of physical memory and terminates itself if the host has less than 1.5 Gigabytes of physical memory in total.

T1497.001
System Checks
MalwareRaspberry Robin

Raspberry Robin performs a variety of system environment checks to determine if it is running in a virtualized or sandboxed environment, such as querying CPU temperature information and network card MAC address information.

T1497.001
System Checks
MalwareMispadu

Mispadu can run checks to verify if it is running within a virtualized environments including Hyper-V, VirtualBox or VMWare and will terminate execution if the computer name is “JOHN-PC.”

T1497.001
System Checks
MalwareUBoatRAT

UBoatRAT checks for virtualization software such as VMWare, VirtualBox, or QEmu on the compromised machine.

T1497.001
System Checks
MalwareNightdoor

Nightdoor embeds code from the public `al-khaser` project, a repository that works to detect virtual machines, sandboxes, and malware analysis environments.

T1497.001
System Checks
MalwareLucifer

Lucifer can check for specific usernames, computer names, device drivers, DLL's, and virtual devices associated with sandboxed environments and can enter an infinite loop and stop itself if any are detected.

T1497.001
System Checks
MalwareObliqueRAT

ObliqueRAT can halt execution if it identifies processes belonging to virtual machine software or analysis tools.

T1497.001
System Checks
MalwareGoldMax

GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to c8:27:cc:c2:37:5a.

T1497.001
System Checks
MalwareDarkTortilla

DarkTortilla can search a compromised system's running processes and services to detect Hyper-V, QEMU, Virtual PC, Virtual Box, and VMware, as well as Sandboxie.

T1497.001
System Checks
MalwareROKRAT

ROKRAT can check for VMware-related files and DLLs related to sandboxes.

T1497.001
System Checks
MalwareExbyte

Exbyte performs various checks to determine if it is running in a sandboxed environment to prevent analysis.

T1497.001
System Checks
MalwareDyre

Dyre can detect sandbox analysis environments by inspecting the process list and Registry.

T1497.001
System Checks
MalwarePlugX

PlugX checks if VMware tools is running in the background by searching for any process named "vmtoolsd".

T1497.001
System Checks
MalwareLumma Stealer

Lumma Stealer has queried system resources on the victim device to identify if it is executing in a sandbox or virtualized environments, checking usernames, conducting WMI queries for system details, checking for files commonly found in virtualized environments, searching system services, and inspecting process names. Lumma Stealer has checked system GPU configurations for sandbox detection.

T1497.001
System Checks
MalwareDarkGate

DarkGate queries system resources on an infected machine to identify if it is executing in a sandbox or virtualized environment.

T1497.001
System Checks
MalwareSVCReady

SVCReady has the ability to determine if its runtime environment is virtualized.

T1497.001
System Checks
MalwareFerocious

Ferocious can run anti-sandbox checks using the Microsoft Excel 4.0 function GET.WORKSPACE to determine the OS version, if there is a mouse present, and if the host is capable of playing sounds.

T1497.001
System Checks
MalwareLatrodectus

Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address.

T1497.001
System Checks
MalwareSaint Bot

Saint Bot has run several virtual machine and sandbox checks, including checking if `Sbiedll.dll` is present in a list of loaded modules, comparing the machine name to `HAL9TH` and the user name to `JohnDoe`, and checking the BIOS version for known virtual machine identifiers.

T1497.001
System Checks
MalwareP8RAT

P8RAT can check the compromised host for processes associated with VMware or VirtualBox environments.

T1497.001
System Checks
MalwareTrojan.Karagany

Trojan.Karagany can detect commonly used and generic virtualization platforms based primarily on drivers and file paths.

T1497.001
System Checks
MalwareBLUELIGHT

BLUELIGHT can check to see if the infected machine has VM tools running.

T1497.001
System Checks
MalwareBlack Basta

Black Basta can check system flags and libraries, process timing, and API's to detect code emulation or sandboxing.

T1497.001
System Checks
MalwareOopsIE

OopsIE performs several anti-VM and sandbox checks on the victim's machine. One technique the group has used was to perform a WMI query SELECT * FROM MSAcpi_ThermalZoneTemperature to check the temperature to see if it’s running in a virtual environment.

T1497.001
System Checks
MalwareRogueRobin

RogueRobin uses WMI to check BIOS version for VBOX, bochs, qemu, virtualbox, and vm to check for evidence that the script might be executing within an analysis environment.

T1497.001
System Checks
MalwareAttor

Attor can detect whether it is executed in some virtualized or emulated environment by searching for specific artifacts, such as communication with I/O ports and using VM-specific instructions.

T1497.001
System Checks
MalwareMegaCortex

MegaCortex has checked the number of CPUs in the system to avoid being run in a sandbox or emulator.

T1497.001
System Checks
MalwareBlackByte Ransomware

BlackByte Ransomware checks for files related to known sandboxes.

T1497.001
System Checks
MalwareSodaMaster

SodaMaster can check for the presence of the Registry key HKEY_CLASSES_ROOT\\Applications\\VMwareHostOpen.exe before proceeding to its main functionality.

T1497.001
System Checks
MalwareGrandoreiro

Grandoreiro can detect VMWare via its I/O port and Virtual PC via the vpcext instruction.

T1497.001
System Checks
MalwareShark

Shark can stop execution if the screen width of the targeted machine is not over 600 pixels.

T1497.001
System Checks
MalwareBadPatch

BadPatch attempts to detect if it is being run in a Virtual Machine (VM) using a WMI query for disk drive name, BIOS, and motherboard information.

T1497.001
System Checks
MalwareXLoader

XLoader performs timing checks using the Read-Time Stamp Counter (RDTSC) instruction on the victim CPU.

T1497.001
System Checks
MalwareFinFisher

FinFisher obtains the hardware device list and checks if the MD5 of the vendor ID is equal to a predefined list in order to check for sandbox/virtualized environments.

T1497.001
System Checks
MalwareSUNBURST

SUNBURST checked the domain name of the compromised host to verify it was running in a real environment.

T1497.001
System Checks
MalwareEvilBunny

EvilBunny's dropper has checked the number of processes and the length and strings of its own file name to identify if the malware is in a sandbox environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.