Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1497.001 System Checks |
MalwareAstaroth | Astaroth can check for Windows product ID's used by sandboxes and usernames and disk serial numbers associated with analyst environments. |
| T1497.001 System Checks |
MalwareQakBot | QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found. |
| T1497.001 System Checks |
MalwareDenis | Denis ran multiple system checks, looking for processor and register characteristics, to evade emulation and analysis. |
| T1497.001 System Checks |
ToolCSPY Downloader | CSPY Downloader can search loaded modules, PEB structure, file paths, Registry keys, and memory to determine if it is being debugged or running in a virtual environment. |
| T1497.001 System Checks |
ToolAsyncRAT | AsyncRAT can identify strings such as Virtual, vmware, or VirtualBox to detect virtualized environments. |
| T1497.001 System Checks |
ToolRemcos | Remcos searches for Sandboxie and VMware on the system. |
| T1497.001 System Checks |
ToolPupy | Pupy has a module that checks a number of indicators on the system to determine if its running on a virtual machine. |
| T1497.001 System Checks |
MalwareMini Shai-Hulud | Mini Shai-Hulud has evaded execution in virtual environments and sandboxes through checking system information to include the number of CPUs and exiting at times when there were less than four and other times when there were less than two CPUs. |
| T1497.002 User Activity Based Checks |
MalwareSpark | Spark has used a splash screen to check whether an user actively clicks on the screen before running malicious code. |
| T1497.002 User Activity Based Checks |
MalwareROAMINGHOUSE | ROAMINGHOUSE can check for specific mouse movements and user activity before initiating malicious activity. |
| T1497.002 User Activity Based Checks |
MalwareTONESHELL | TONESHELL has leveraged `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle. |
| T1497.002 User Activity Based Checks |
MalwareOkrum | Okrum loader only executes the payload after the left mouse button has been pressed at least three times, in order to avoid being executed within virtualized or emulated environments. |
| T1497.002 User Activity Based Checks |
MalwareCobalt Strike | The Cobalt Strike loader can use the `MessageBoxA` API to prompt for user interaction as an anti-sandbox measure. |
| T1497.003 Time Based Checks |
MalwareTrickBot | TrickBot has used |
| T1497.003 Time Based Checks |
MalwareBumblebee | Bumblebee has the ability to set a hardcoded and randomized sleep interval. |
| T1497.003 Time Based Checks |
MalwareUrsnif | Ursnif has used a 30 minute delay after execution to evade sandbox monitoring tools. |
| T1497.003 Time Based Checks |
MalwareRansomHub | RansomHub can sleep for a set number of minutes before beginning execution. |
| T1497.003 Time Based Checks |
MalwareHavoc | The Havoc demon agent can be set to sleep for a specified time. |
| T1497.003 Time Based Checks |
MalwarePony | Pony has delayed execution using a built-in function to avoid detection and analysis. |
| T1497.003 Time Based Checks |
MalwareCrimson | Crimson can determine when it has been installed on a host for at least 15 days before downloading the final payload. |
| T1497.003 Time Based Checks |
MalwareTomiris | Tomiris has the ability to sleep for at least nine minutes to evade sandbox-based analysis systems. |
| T1497.003 Time Based Checks |
MalwareGootloader | Gootloader can designate a sleep period of more than 22 seconds between stages of infection. |
| T1497.003 Time Based Checks |
MalwareSnip3 | Snip3 can execute `WScript.Sleep` to delay execution of its second stage. |
| T1497.003 Time Based Checks |
MalwareGuLoader | GuLoader has the ability to perform anti-debugging based on time checks, API calls, and CPUID. |
| T1497.003 Time Based Checks |
MalwareWhisperGate | WhisperGate can pause for 20 seconds to bypass antivirus solutions. |
| T1497.003 Time Based Checks |
MalwareOkrum | Okrum's loader can detect presence of an emulator by using two calls to GetTickCount API, and checking whether the time has been accelerated. |
| T1497.003 Time Based Checks |
MalwareRaindrop | After initial installation, Raindrop runs a computation to delay execution. |
| T1497.003 Time Based Checks |
MalwareFatDuke | FatDuke can turn itself on or off at random intervals. |
| T1497.003 Time Based Checks |
MalwareDRATzarus | DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing. DRATzarus can also remotely shut down into sleep mode under specific conditions to evade |
| T1497.003 Time Based Checks |
MalwareGoldMax | GoldMax has set an execution trigger date and time, stored as an ASCII Unix/Epoch time value. |
| T1497.003 Time Based Checks |
MalwareDarkTortilla | DarkTortilla can implement the `kernel32.dll` Sleep function to delay execution for up to 300 seconds before implementing persistence or processing an addon package. |
| T1497.003 Time Based Checks |
MalwareBisonal | Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing. |
| T1497.003 Time Based Checks |
MalwareClambling | Clambling can wait 30 minutes before initiating contact with C2. |
| T1497.003 Time Based Checks |
MalwareSVCReady | SVCReady can enter a sleep stage for 30 minutes to evade detection. |
| T1497.003 Time Based Checks |
MalwareThiefQuest | ThiefQuest invokes |
| T1497.003 Time Based Checks |
MalwareSaint Bot | Saint Bot has used the command `timeout 20` to pause the execution of its initial loader. |
| T1497.003 Time Based Checks |
MalwareP8RAT | P8RAT has the ability to "sleep" for a specified time to evade detection. |
| T1497.003 Time Based Checks |
MalwareBendyBear | BendyBear can check for analysis environments and signs of debugging using the Windows API |
| T1497.003 Time Based Checks |
MalwareSodaMaster | SodaMaster has the ability to put itself to "sleep" for a specified time. |
| T1497.003 Time Based Checks |
MalwareLiteDuke | LiteDuke can wait 30 seconds before executing additional code if security software is detected. |
| T1497.003 Time Based Checks |
MalwareBazar | Bazar can use a timer to delay execution of core functionality. |
| T1497.003 Time Based Checks |
MalwareHiddenFace | HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis. |
| T1497.003 Time Based Checks |
MalwareHermeticWiper | HermeticWiper has the ability to receive a command parameter to sleep prior to carrying out destructive actions on a targeted host. |
| T1497.003 Time Based Checks |
MalwareSUNBURST | SUNBURST remained dormant after initial access for a period of up to two weeks. |
| T1497.003 Time Based Checks |
MalwareEvilBunny | EvilBunny has used time measurements from 3 different APIs before and after performing sleep operations to check and abort if the malware is running in a sandbox. |
| T1497.003 Time Based Checks |
MalwareIPsec Helper | IPsec Helper will sleep for a random number of seconds, iterating 200 times over sleeps between one to three seconds, before continuing execution flow. |
| T1497.003 Time Based Checks |
MalwareGoldenSpy | GoldenSpy's installer has delayed installation of GoldenSpy for two hours after it reaches a victim system. |
| T1497.003 Time Based Checks |
MalwareGrimAgent | GrimAgent can sleep for 195 - 205 seconds after payload execution and before deleting its task. |
| T1497.003 Time Based Checks |
MalwareClop | Clop has used the |
| T1497.003 Time Based Checks |
MalwareLokibot | Lokibot has performed a time-based anti-debug check before downloading its third stage. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.