ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1497.001×

61 examples

TechniqueUsed byProcedure example
T1497.001
System Checks
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D checks a number of system parameters to see if it is being run on real hardware or in a virtual machine environment, such as `sysctl hw.model` and the kernel boot time.

T1497.001
System Checks
MalwareNativeZone

NativeZone has checked if Vmware or VirtualBox VM is running on a compromised host.

T1497.001
System Checks
MalwarePoetRAT

PoetRAT checked the size of the hard drive to determine if it was being run in a sandbox environment. In the event of sandbox detection, it would delete itself by overwriting the malware scripts with the contents of "License.txt" and exiting.

T1497.001
System Checks
MalwareAstaroth

Astaroth can check for Windows product ID's used by sandboxes and usernames and disk serial numbers associated with analyst environments.

T1497.001
System Checks
MalwareQakBot

QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found.

T1497.001
System Checks
MalwareDenis

Denis ran multiple system checks, looking for processor and register characteristics, to evade emulation and analysis.

T1497.001
System Checks
ToolCSPY Downloader

CSPY Downloader can search loaded modules, PEB structure, file paths, Registry keys, and memory to determine if it is being debugged or running in a virtual environment.

T1497.001
System Checks
ToolAsyncRAT

AsyncRAT can identify strings such as Virtual, vmware, or VirtualBox to detect virtualized environments.

T1497.001
System Checks
ToolRemcos

Remcos searches for Sandboxie and VMware on the system.

T1497.001
System Checks
ToolPupy

Pupy has a module that checks a number of indicators on the system to determine if its running on a virtual machine.

T1497.001
System Checks
MalwareMini Shai-Hulud

Mini Shai-Hulud has evaded execution in virtual environments and sandboxes through checking system information to include the number of CPUs and exiting at times when there were less than four and other times when there were less than two CPUs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.