Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1497 Virtualization/Sandbox Evasion |
MalwareBumblebee | Bumblebee has the ability to perform anti-virtualization checks. |
| T1497 Virtualization/Sandbox Evasion |
MalwareSquirrelwaffle | Squirrelwaffle has contained a hardcoded list of IP addresses to block that belong to sandboxes and analysis platforms. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRaspberry Robin | Raspberry Robin contains real and fake second-stage payloads following initial execution, with the real payload only delivered if the malware determines it is not running in a virtualized environment. |
| T1497 Virtualization/Sandbox Evasion |
MalwareIcedID | IcedID has manipulated Keitaro Traffic Direction System to filter researcher and sandbox traffic. |
| T1497 Virtualization/Sandbox Evasion |
MalwarePteranodon | Pteranodon has the ability to use anti-detection functions to identify sandbox environments. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBisonal | Bisonal can check to determine if the compromised system is running on VMware. |
| T1497 Virtualization/Sandbox Evasion |
MalwareMetamorfo | Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRedLine Stealer | RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBlack Basta | Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis. |
| T1497 Virtualization/Sandbox Evasion |
MalwareStoneDrill | StoneDrill has used several anti-emulation techniques to prevent automated analysis by emulators or sandboxes. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRTM | RTM can detect if it is running within a sandbox or other virtualized analysis environment. |
| T1497 Virtualization/Sandbox Evasion |
MalwareStrelaStealer | StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBazar | Bazar can attempt to overload sandbox analysis by sending 1550 calls to |
| T1497 Virtualization/Sandbox Evasion |
MalwareXLoader | XLoader can utilize decoy command and control domains within the malware configuration to circumvent sandbox analysis. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCarberp | Carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software. |
| T1497 Virtualization/Sandbox Evasion |
MalwareEgregor | Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCHOPSTICK | CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCozyCar | Some versions of CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. If it detects that it is, it will exit. |
| T1497 Virtualization/Sandbox Evasion |
MalwareKevin | Kevin can sleep for a time interval between C2 communication attempts. |
| T1497 Virtualization/Sandbox Evasion |
MalwareAgent Tesla | Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. |
| T1497 Virtualization/Sandbox Evasion |
MalwareHancitor | Hancitor has used a macro to check that an ActiveDocument shape object in the lure message is present. If this object is not found, the macro will exit without downloading additional payloads. |
| T1497 Virtualization/Sandbox Evasion |
MalwareGelsemium | Gelsemium can use junk code to generate random activity to obscure malware behavior. |
| T1497 Virtualization/Sandbox Evasion |
MalwareMini Shai-Hulud | Mini Shai-Hulud has evaded sandbox detection by applying a 1-in-6 probability gate that generates a random number which will only trigger the wiper functionality when the set number outcome is met even in environments that match parameters of a geopolitical target. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.