ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1497.001
System Checks
MalwareBLUELIGHT

BLUELIGHT can check to see if the infected machine has VM tools running.

T1497.001
System Checks
MalwareBlack Basta

Black Basta can check system flags and libraries, process timing, and API's to detect code emulation or sandboxing.

T1497.001
System Checks
MalwareOopsIE

OopsIE performs several anti-VM and sandbox checks on the victim's machine. One technique the group has used was to perform a WMI query SELECT * FROM MSAcpi_ThermalZoneTemperature to check the temperature to see if it’s running in a virtual environment.

T1497.001
System Checks
MalwareRogueRobin

RogueRobin uses WMI to check BIOS version for VBOX, bochs, qemu, virtualbox, and vm to check for evidence that the script might be executing within an analysis environment.

T1497.001
System Checks
MalwareAttor

Attor can detect whether it is executed in some virtualized or emulated environment by searching for specific artifacts, such as communication with I/O ports and using VM-specific instructions.

T1497.001
System Checks
MalwareMegaCortex

MegaCortex has checked the number of CPUs in the system to avoid being run in a sandbox or emulator.

T1497.001
System Checks
MalwareBlackByte Ransomware

BlackByte Ransomware checks for files related to known sandboxes.

T1497.001
System Checks
MalwareSodaMaster

SodaMaster can check for the presence of the Registry key HKEY_CLASSES_ROOT\\Applications\\VMwareHostOpen.exe before proceeding to its main functionality.

T1497.001
System Checks
MalwareGrandoreiro

Grandoreiro can detect VMWare via its I/O port and Virtual PC via the vpcext instruction.

T1497.001
System Checks
MalwareShark

Shark can stop execution if the screen width of the targeted machine is not over 600 pixels.

T1497.001
System Checks
MalwareBadPatch

BadPatch attempts to detect if it is being run in a Virtual Machine (VM) using a WMI query for disk drive name, BIOS, and motherboard information.

T1497.001
System Checks
MalwareXLoader

XLoader performs timing checks using the Read-Time Stamp Counter (RDTSC) instruction on the victim CPU.

T1497.001
System Checks
MalwareFinFisher

FinFisher obtains the hardware device list and checks if the MD5 of the vendor ID is equal to a predefined list in order to check for sandbox/virtualized environments.

T1497.001
System Checks
MalwareSUNBURST

SUNBURST checked the domain name of the compromised host to verify it was running in a real environment.

T1497.001
System Checks
MalwareEvilBunny

EvilBunny's dropper has checked the number of processes and the length and strings of its own file name to identify if the malware is in a sandbox environment.

T1497.001
System Checks
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D checks a number of system parameters to see if it is being run on real hardware or in a virtual machine environment, such as `sysctl hw.model` and the kernel boot time.

T1497.001
System Checks
MalwareNativeZone

NativeZone has checked if Vmware or VirtualBox VM is running on a compromised host.

T1497.001
System Checks
MalwarePoetRAT

PoetRAT checked the size of the hard drive to determine if it was being run in a sandbox environment. In the event of sandbox detection, it would delete itself by overwriting the malware scripts with the contents of "License.txt" and exiting.

T1497.001
System Checks
MalwareAstaroth

Astaroth can check for Windows product ID's used by sandboxes and usernames and disk serial numbers associated with analyst environments.

T1497.001
System Checks
MalwareQakBot

QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found.

T1497.001
System Checks
MalwareDenis

Denis ran multiple system checks, looking for processor and register characteristics, to evade emulation and analysis.

T1497.001
System Checks
ToolCSPY Downloader

CSPY Downloader can search loaded modules, PEB structure, file paths, Registry keys, and memory to determine if it is being debugged or running in a virtual environment.

T1497.001
System Checks
ToolAsyncRAT

AsyncRAT can identify strings such as Virtual, vmware, or VirtualBox to detect virtualized environments.

T1497.001
System Checks
ToolRemcos

Remcos searches for Sandboxie and VMware on the system.

T1497.001
System Checks
ToolPupy

Pupy has a module that checks a number of indicators on the system to determine if its running on a virtual machine.

T1497.001
System Checks
MalwareMini Shai-Hulud

Mini Shai-Hulud has evaded execution in virtual environments and sandboxes through checking system information to include the number of CPUs and exiting at times when there were less than four and other times when there were less than two CPUs.

T1497.002
User Activity Based Checks
GroupFIN7

FIN7 used images embedded into document lures that only activate the payload when a user double clicks to avoid sandboxes.

T1497.002
User Activity Based Checks
GroupDarkhotel

Darkhotel has used malware that repeatedly checks the mouse cursor position to determine if a real user is on the system.

T1497.002
User Activity Based Checks
MalwareSpark

Spark has used a splash screen to check whether an user actively clicks on the screen before running malicious code.

T1497.002
User Activity Based Checks
MalwareROAMINGHOUSE

ROAMINGHOUSE can check for specific mouse movements and user activity before initiating malicious activity.

T1497.002
User Activity Based Checks
MalwareTONESHELL

TONESHELL has leveraged `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle.

T1497.002
User Activity Based Checks
MalwareOkrum

Okrum loader only executes the payload after the left mouse button has been pressed at least three times, in order to avoid being executed within virtualized or emulated environments.

T1497.002
User Activity Based Checks
MalwareCobalt Strike

The Cobalt Strike loader can use the `MessageBoxA` API to prompt for user interaction as an anti-sandbox measure.

T1497.003
Time Based Checks
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services.

T1497.003
Time Based Checks
MalwareTrickBot

TrickBot has used printf and file I/O loops to delay process execution as part of API hammering.

T1497.003
Time Based Checks
MalwareBumblebee

Bumblebee has the ability to set a hardcoded and randomized sleep interval.

T1497.003
Time Based Checks
MalwareUrsnif

Ursnif has used a 30 minute delay after execution to evade sandbox monitoring tools.

T1497.003
Time Based Checks
MalwareRansomHub

RansomHub can sleep for a set number of minutes before beginning execution.

T1497.003
Time Based Checks
MalwareHavoc

The Havoc demon agent can be set to sleep for a specified time.

T1497.003
Time Based Checks
MalwarePony

Pony has delayed execution using a built-in function to avoid detection and analysis.

T1497.003
Time Based Checks
MalwareCrimson

Crimson can determine when it has been installed on a host for at least 15 days before downloading the final payload.

T1497.003
Time Based Checks
MalwareTomiris

Tomiris has the ability to sleep for at least nine minutes to evade sandbox-based analysis systems.

T1497.003
Time Based Checks
MalwareGootloader

Gootloader can designate a sleep period of more than 22 seconds between stages of infection.

T1497.003
Time Based Checks
MalwareSnip3

Snip3 can execute `WScript.Sleep` to delay execution of its second stage.

T1497.003
Time Based Checks
MalwareGuLoader

GuLoader has the ability to perform anti-debugging based on time checks, API calls, and CPUID.

T1497.003
Time Based Checks
MalwareWhisperGate

WhisperGate can pause for 20 seconds to bypass antivirus solutions.

T1497.003
Time Based Checks
MalwareOkrum

Okrum's loader can detect presence of an emulator by using two calls to GetTickCount API, and checking whether the time has been accelerated.

T1497.003
Time Based Checks
MalwareRaindrop

After initial installation, Raindrop runs a computation to delay execution.

T1497.003
Time Based Checks
MalwareFatDuke

FatDuke can turn itself on or off at random intervals.

T1497.003
Time Based Checks
MalwareDRATzarus

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing. DRATzarus can also remotely shut down into sleep mode under specific conditions to evade
detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.