Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1497.001 System Checks |
MalwareBLUELIGHT | BLUELIGHT can check to see if the infected machine has VM tools running. |
| T1497.001 System Checks |
MalwareBlack Basta | Black Basta can check system flags and libraries, process timing, and API's to detect code emulation or sandboxing. |
| T1497.001 System Checks |
MalwareOopsIE | OopsIE performs several anti-VM and sandbox checks on the victim's machine. One technique the group has used was to perform a WMI query |
| T1497.001 System Checks |
MalwareRogueRobin | RogueRobin uses WMI to check BIOS version for VBOX, bochs, qemu, virtualbox, and vm to check for evidence that the script might be executing within an analysis environment. |
| T1497.001 System Checks |
MalwareAttor | Attor can detect whether it is executed in some virtualized or emulated environment by searching for specific artifacts, such as communication with I/O ports and using VM-specific instructions. |
| T1497.001 System Checks |
MalwareMegaCortex | MegaCortex has checked the number of CPUs in the system to avoid being run in a sandbox or emulator. |
| T1497.001 System Checks |
MalwareBlackByte Ransomware | BlackByte Ransomware checks for files related to known sandboxes. |
| T1497.001 System Checks |
MalwareSodaMaster | SodaMaster can check for the presence of the Registry key |
| T1497.001 System Checks |
MalwareGrandoreiro | Grandoreiro can detect VMWare via its I/O port and Virtual PC via the |
| T1497.001 System Checks |
MalwareShark | Shark can stop execution if the screen width of the targeted machine is not over 600 pixels. |
| T1497.001 System Checks |
MalwareBadPatch | BadPatch attempts to detect if it is being run in a Virtual Machine (VM) using a WMI query for disk drive name, BIOS, and motherboard information. |
| T1497.001 System Checks |
MalwareXLoader | XLoader performs timing checks using the Read-Time Stamp Counter (RDTSC) instruction on the victim CPU. |
| T1497.001 System Checks |
MalwareFinFisher | FinFisher obtains the hardware device list and checks if the MD5 of the vendor ID is equal to a predefined list in order to check for sandbox/virtualized environments. |
| T1497.001 System Checks |
MalwareSUNBURST | SUNBURST checked the domain name of the compromised host to verify it was running in a real environment. |
| T1497.001 System Checks |
MalwareEvilBunny | EvilBunny's dropper has checked the number of processes and the length and strings of its own file name to identify if the malware is in a sandbox environment. |
| T1497.001 System Checks |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D checks a number of system parameters to see if it is being run on real hardware or in a virtual machine environment, such as `sysctl hw.model` and the kernel boot time. |
| T1497.001 System Checks |
MalwareNativeZone | NativeZone has checked if Vmware or VirtualBox VM is running on a compromised host. |
| T1497.001 System Checks |
MalwarePoetRAT | PoetRAT checked the size of the hard drive to determine if it was being run in a sandbox environment. In the event of sandbox detection, it would delete itself by overwriting the malware scripts with the contents of "License.txt" and exiting. |
| T1497.001 System Checks |
MalwareAstaroth | Astaroth can check for Windows product ID's used by sandboxes and usernames and disk serial numbers associated with analyst environments. |
| T1497.001 System Checks |
MalwareQakBot | QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found. |
| T1497.001 System Checks |
MalwareDenis | Denis ran multiple system checks, looking for processor and register characteristics, to evade emulation and analysis. |
| T1497.001 System Checks |
ToolCSPY Downloader | CSPY Downloader can search loaded modules, PEB structure, file paths, Registry keys, and memory to determine if it is being debugged or running in a virtual environment. |
| T1497.001 System Checks |
ToolAsyncRAT | AsyncRAT can identify strings such as Virtual, vmware, or VirtualBox to detect virtualized environments. |
| T1497.001 System Checks |
ToolRemcos | Remcos searches for Sandboxie and VMware on the system. |
| T1497.001 System Checks |
ToolPupy | Pupy has a module that checks a number of indicators on the system to determine if its running on a virtual machine. |
| T1497.001 System Checks |
MalwareMini Shai-Hulud | Mini Shai-Hulud has evaded execution in virtual environments and sandboxes through checking system information to include the number of CPUs and exiting at times when there were less than four and other times when there were less than two CPUs. |
| T1497.002 User Activity Based Checks |
GroupFIN7 | FIN7 used images embedded into document lures that only activate the payload when a user double clicks to avoid sandboxes. |
| T1497.002 User Activity Based Checks |
GroupDarkhotel | Darkhotel has used malware that repeatedly checks the mouse cursor position to determine if a real user is on the system. |
| T1497.002 User Activity Based Checks |
MalwareSpark | Spark has used a splash screen to check whether an user actively clicks on the screen before running malicious code. |
| T1497.002 User Activity Based Checks |
MalwareROAMINGHOUSE | ROAMINGHOUSE can check for specific mouse movements and user activity before initiating malicious activity. |
| T1497.002 User Activity Based Checks |
MalwareTONESHELL | TONESHELL has leveraged `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle. |
| T1497.002 User Activity Based Checks |
MalwareOkrum | Okrum loader only executes the payload after the left mouse button has been pressed at least three times, in order to avoid being executed within virtualized or emulated environments. |
| T1497.002 User Activity Based Checks |
MalwareCobalt Strike | The Cobalt Strike loader can use the `MessageBoxA` API to prompt for user interaction as an anti-sandbox measure. |
| T1497.003 Time Based Checks |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services. |
| T1497.003 Time Based Checks |
MalwareTrickBot | TrickBot has used |
| T1497.003 Time Based Checks |
MalwareBumblebee | Bumblebee has the ability to set a hardcoded and randomized sleep interval. |
| T1497.003 Time Based Checks |
MalwareUrsnif | Ursnif has used a 30 minute delay after execution to evade sandbox monitoring tools. |
| T1497.003 Time Based Checks |
MalwareRansomHub | RansomHub can sleep for a set number of minutes before beginning execution. |
| T1497.003 Time Based Checks |
MalwareHavoc | The Havoc demon agent can be set to sleep for a specified time. |
| T1497.003 Time Based Checks |
MalwarePony | Pony has delayed execution using a built-in function to avoid detection and analysis. |
| T1497.003 Time Based Checks |
MalwareCrimson | Crimson can determine when it has been installed on a host for at least 15 days before downloading the final payload. |
| T1497.003 Time Based Checks |
MalwareTomiris | Tomiris has the ability to sleep for at least nine minutes to evade sandbox-based analysis systems. |
| T1497.003 Time Based Checks |
MalwareGootloader | Gootloader can designate a sleep period of more than 22 seconds between stages of infection. |
| T1497.003 Time Based Checks |
MalwareSnip3 | Snip3 can execute `WScript.Sleep` to delay execution of its second stage. |
| T1497.003 Time Based Checks |
MalwareGuLoader | GuLoader has the ability to perform anti-debugging based on time checks, API calls, and CPUID. |
| T1497.003 Time Based Checks |
MalwareWhisperGate | WhisperGate can pause for 20 seconds to bypass antivirus solutions. |
| T1497.003 Time Based Checks |
MalwareOkrum | Okrum's loader can detect presence of an emulator by using two calls to GetTickCount API, and checking whether the time has been accelerated. |
| T1497.003 Time Based Checks |
MalwareRaindrop | After initial installation, Raindrop runs a computation to delay execution. |
| T1497.003 Time Based Checks |
MalwareFatDuke | FatDuke can turn itself on or off at random intervals. |
| T1497.003 Time Based Checks |
MalwareDRATzarus | DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing. DRATzarus can also remotely shut down into sleep mode under specific conditions to evade |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.