ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1497×

23 examples

TechniqueUsed byProcedure example
T1497
Virtualization/Sandbox Evasion
MalwareBumblebee

Bumblebee has the ability to perform anti-virtualization checks.

T1497
Virtualization/Sandbox Evasion
MalwareSquirrelwaffle

Squirrelwaffle has contained a hardcoded list of IP addresses to block that belong to sandboxes and analysis platforms.

T1497
Virtualization/Sandbox Evasion
MalwareRaspberry Robin

Raspberry Robin contains real and fake second-stage payloads following initial execution, with the real payload only delivered if the malware determines it is not running in a virtualized environment.

T1497
Virtualization/Sandbox Evasion
MalwareIcedID

IcedID has manipulated Keitaro Traffic Direction System to filter researcher and sandbox traffic.

T1497
Virtualization/Sandbox Evasion
MalwarePteranodon

Pteranodon has the ability to use anti-detection functions to identify sandbox environments.

T1497
Virtualization/Sandbox Evasion
MalwareBisonal

Bisonal can check to determine if the compromised system is running on VMware.

T1497
Virtualization/Sandbox Evasion
MalwareMetamorfo

Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution.

T1497
Virtualization/Sandbox Evasion
MalwareRedLine Stealer

RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution.

T1497
Virtualization/Sandbox Evasion
MalwareBlack Basta

Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis.

T1497
Virtualization/Sandbox Evasion
MalwareStoneDrill

StoneDrill has used several anti-emulation techniques to prevent automated analysis by emulators or sandboxes.

T1497
Virtualization/Sandbox Evasion
MalwareRTM

RTM can detect if it is running within a sandbox or other virtualized analysis environment.

T1497
Virtualization/Sandbox Evasion
MalwareStrelaStealer

StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods.

T1497
Virtualization/Sandbox Evasion
MalwareBazar

Bazar can attempt to overload sandbox analysis by sending 1550 calls to printf.

T1497
Virtualization/Sandbox Evasion
MalwareXLoader

XLoader can utilize decoy command and control domains within the malware configuration to circumvent sandbox analysis.

T1497
Virtualization/Sandbox Evasion
MalwareCarberp

Carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software.

T1497
Virtualization/Sandbox Evasion
MalwareEgregor

Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes.

T1497
Virtualization/Sandbox Evasion
MalwareCHOPSTICK

CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it.

T1497
Virtualization/Sandbox Evasion
MalwareCozyCar

Some versions of CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. If it detects that it is, it will exit.

T1497
Virtualization/Sandbox Evasion
MalwareKevin

Kevin can sleep for a time interval between C2 communication attempts.

T1497
Virtualization/Sandbox Evasion
MalwareAgent Tesla

Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks.

T1497
Virtualization/Sandbox Evasion
MalwareHancitor

Hancitor has used a macro to check that an ActiveDocument shape object in the lure message is present. If this object is not found, the macro will exit without downloading additional payloads.

T1497
Virtualization/Sandbox Evasion
MalwareGelsemium

Gelsemium can use junk code to generate random activity to obscure malware behavior.

T1497
Virtualization/Sandbox Evasion
MalwareMini Shai-Hulud

Mini Shai-Hulud has evaded sandbox detection by applying a 1-in-6 probability gate that generates a random number which will only trigger the wiper functionality when the set number outcome is met even in environments that match parameters of a geopolitical target.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.