Real-world descriptions of how a group, tool or campaign used a technique.
61 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1497.001 System Checks |
MalwarePikabot | Pikabot performs a variety of system checks to determine if it is running in an analysis environment or sandbox, such as checking the number of processors (must be greater than two), and the amount of RAM (must be greater than 2GB). |
| T1497.001 System Checks |
MalwareSynAck | SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
| T1497.001 System Checks |
MalwareBumblebee | Bumblebee has the ability to search for designated file paths and Registry keys that indicate a virtualized environment from multiple products. |
| T1497.001 System Checks |
Malwareyty | yty has some basic anti-sandbox detection that tries to detect Virtual PC, Sandboxie, and VMware. |
| T1497.001 System Checks |
MalwareSmoke Loader | Smoke Loader scans processes to perform anti-VM checks. |
| T1497.001 System Checks |
MalwareHeartCrypt | HeartCrypt will attempt to load non-existent DLLs in attempt to detect sandbox creation of a dummy DLL to prevent the program from crashing. |
| T1497.001 System Checks |
MalwareGravityRAT | GravityRAT uses WMI to check the BIOS and manufacturer information for strings like "VMWare", "Virtual", and "XEN" and another WMI request to get the current temperature of the hardware to determine if it's a virtual machine environment. |
| T1497.001 System Checks |
MalwaremacOS.OSAMiner | macOS.OSAMiner can parse the output of the native `system_profiler` tool to determine if the machine is running with 4 cores. |
| T1497.001 System Checks |
MalwareDUSTTRAP | DUSTTRAP decryption relies on the infected machine's `HKLM\SOFTWARE\Microsoft\Cryptography\MachineGUID` value. |
| T1497.001 System Checks |
MalwareSnip3 | Snip3 has the ability to detect Windows Sandbox, VMWare, or VirtualBox by querying `Win32_ComputerSystem` to extract the `Manufacturer` string. |
| T1497.001 System Checks |
MalwareGuLoader | GuLoader has the ability to perform anti-VM and anti-sandbox checks using string hashing, the API call |
| T1497.001 System Checks |
MalwareWastedLocker | WastedLocker checked if UCOMIEnumConnections and IActiveScriptParseProcedure32 Registry keys were detected as part of its anti-analysis technique. |
| T1497.001 System Checks |
MalwareInvisiMole | InvisiMole can check for artifacts of VirtualBox, Virtual PC and VMware environment, and terminate itself if they are detected. |
| T1497.001 System Checks |
MalwareWhisperGate | WhisperGate can stop its execution when it recognizes the presence of certain monitoring tools. |
| T1497.001 System Checks |
MalwareOkrum | Okrum's loader can check the amount of physical memory and terminates itself if the host has less than 1.5 Gigabytes of physical memory in total. |
| T1497.001 System Checks |
MalwareRaspberry Robin | Raspberry Robin performs a variety of system environment checks to determine if it is running in a virtualized or sandboxed environment, such as querying CPU temperature information and network card MAC address information. |
| T1497.001 System Checks |
MalwareMispadu | Mispadu can run checks to verify if it is running within a virtualized environments including Hyper-V, VirtualBox or VMWare and will terminate execution if the computer name is “JOHN-PC.” |
| T1497.001 System Checks |
MalwareUBoatRAT | UBoatRAT checks for virtualization software such as VMWare, VirtualBox, or QEmu on the compromised machine. |
| T1497.001 System Checks |
MalwareNightdoor | Nightdoor embeds code from the public `al-khaser` project, a repository that works to detect virtual machines, sandboxes, and malware analysis environments. |
| T1497.001 System Checks |
MalwareLucifer | Lucifer can check for specific usernames, computer names, device drivers, DLL's, and virtual devices associated with sandboxed environments and can enter an infinite loop and stop itself if any are detected. |
| T1497.001 System Checks |
MalwareObliqueRAT | ObliqueRAT can halt execution if it identifies processes belonging to virtual machine software or analysis tools. |
| T1497.001 System Checks |
MalwareGoldMax | GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to |
| T1497.001 System Checks |
MalwareDarkTortilla | DarkTortilla can search a compromised system's running processes and services to detect Hyper-V, QEMU, Virtual PC, Virtual Box, and VMware, as well as Sandboxie. |
| T1497.001 System Checks |
MalwareROKRAT | ROKRAT can check for VMware-related files and DLLs related to sandboxes. |
| T1497.001 System Checks |
MalwareExbyte | Exbyte performs various checks to determine if it is running in a sandboxed environment to prevent analysis. |
| T1497.001 System Checks |
MalwareDyre | Dyre can detect sandbox analysis environments by inspecting the process list and Registry. |
| T1497.001 System Checks |
MalwarePlugX | PlugX checks if VMware tools is running in the background by searching for any process named "vmtoolsd". |
| T1497.001 System Checks |
MalwareLumma Stealer | Lumma Stealer has queried system resources on the victim device to identify if it is executing in a sandbox or virtualized environments, checking usernames, conducting WMI queries for system details, checking for files commonly found in virtualized environments, searching system services, and inspecting process names. Lumma Stealer has checked system GPU configurations for sandbox detection. |
| T1497.001 System Checks |
MalwareDarkGate | DarkGate queries system resources on an infected machine to identify if it is executing in a sandbox or virtualized environment. |
| T1497.001 System Checks |
MalwareSVCReady | SVCReady has the ability to determine if its runtime environment is virtualized. |
| T1497.001 System Checks |
MalwareFerocious | Ferocious can run anti-sandbox checks using the Microsoft Excel 4.0 function |
| T1497.001 System Checks |
MalwareLatrodectus | Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address. |
| T1497.001 System Checks |
MalwareSaint Bot | Saint Bot has run several virtual machine and sandbox checks, including checking if `Sbiedll.dll` is present in a list of loaded modules, comparing the machine name to `HAL9TH` and the user name to `JohnDoe`, and checking the BIOS version for known virtual machine identifiers. |
| T1497.001 System Checks |
MalwareP8RAT | P8RAT can check the compromised host for processes associated with VMware or VirtualBox environments. |
| T1497.001 System Checks |
MalwareTrojan.Karagany | Trojan.Karagany can detect commonly used and generic virtualization platforms based primarily on drivers and file paths. |
| T1497.001 System Checks |
MalwareBLUELIGHT | BLUELIGHT can check to see if the infected machine has VM tools running. |
| T1497.001 System Checks |
MalwareBlack Basta | Black Basta can check system flags and libraries, process timing, and API's to detect code emulation or sandboxing. |
| T1497.001 System Checks |
MalwareOopsIE | OopsIE performs several anti-VM and sandbox checks on the victim's machine. One technique the group has used was to perform a WMI query |
| T1497.001 System Checks |
MalwareRogueRobin | RogueRobin uses WMI to check BIOS version for VBOX, bochs, qemu, virtualbox, and vm to check for evidence that the script might be executing within an analysis environment. |
| T1497.001 System Checks |
MalwareAttor | Attor can detect whether it is executed in some virtualized or emulated environment by searching for specific artifacts, such as communication with I/O ports and using VM-specific instructions. |
| T1497.001 System Checks |
MalwareMegaCortex | MegaCortex has checked the number of CPUs in the system to avoid being run in a sandbox or emulator. |
| T1497.001 System Checks |
MalwareBlackByte Ransomware | BlackByte Ransomware checks for files related to known sandboxes. |
| T1497.001 System Checks |
MalwareSodaMaster | SodaMaster can check for the presence of the Registry key |
| T1497.001 System Checks |
MalwareGrandoreiro | Grandoreiro can detect VMWare via its I/O port and Virtual PC via the |
| T1497.001 System Checks |
MalwareShark | Shark can stop execution if the screen width of the targeted machine is not over 600 pixels. |
| T1497.001 System Checks |
MalwareBadPatch | BadPatch attempts to detect if it is being run in a Virtual Machine (VM) using a WMI query for disk drive name, BIOS, and motherboard information. |
| T1497.001 System Checks |
MalwareXLoader | XLoader performs timing checks using the Read-Time Stamp Counter (RDTSC) instruction on the victim CPU. |
| T1497.001 System Checks |
MalwareFinFisher | FinFisher obtains the hardware device list and checks if the MD5 of the vendor ID is equal to a predefined list in order to check for sandbox/virtualized environments. |
| T1497.001 System Checks |
MalwareSUNBURST | SUNBURST checked the domain name of the compromised host to verify it was running in a real environment. |
| T1497.001 System Checks |
MalwareEvilBunny | EvilBunny's dropper has checked the number of processes and the length and strings of its own file name to identify if the malware is in a sandbox environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.