ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1497.003×

48 examples

TechniqueUsed byProcedure example
T1497.003
Time Based Checks
MalwareTrickBot

TrickBot has used printf and file I/O loops to delay process execution as part of API hammering.

T1497.003
Time Based Checks
MalwareBumblebee

Bumblebee has the ability to set a hardcoded and randomized sleep interval.

T1497.003
Time Based Checks
MalwareUrsnif

Ursnif has used a 30 minute delay after execution to evade sandbox monitoring tools.

T1497.003
Time Based Checks
MalwareRansomHub

RansomHub can sleep for a set number of minutes before beginning execution.

T1497.003
Time Based Checks
MalwareHavoc

The Havoc demon agent can be set to sleep for a specified time.

T1497.003
Time Based Checks
MalwarePony

Pony has delayed execution using a built-in function to avoid detection and analysis.

T1497.003
Time Based Checks
MalwareCrimson

Crimson can determine when it has been installed on a host for at least 15 days before downloading the final payload.

T1497.003
Time Based Checks
MalwareTomiris

Tomiris has the ability to sleep for at least nine minutes to evade sandbox-based analysis systems.

T1497.003
Time Based Checks
MalwareGootloader

Gootloader can designate a sleep period of more than 22 seconds between stages of infection.

T1497.003
Time Based Checks
MalwareSnip3

Snip3 can execute `WScript.Sleep` to delay execution of its second stage.

T1497.003
Time Based Checks
MalwareGuLoader

GuLoader has the ability to perform anti-debugging based on time checks, API calls, and CPUID.

T1497.003
Time Based Checks
MalwareWhisperGate

WhisperGate can pause for 20 seconds to bypass antivirus solutions.

T1497.003
Time Based Checks
MalwareOkrum

Okrum's loader can detect presence of an emulator by using two calls to GetTickCount API, and checking whether the time has been accelerated.

T1497.003
Time Based Checks
MalwareRaindrop

After initial installation, Raindrop runs a computation to delay execution.

T1497.003
Time Based Checks
MalwareFatDuke

FatDuke can turn itself on or off at random intervals.

T1497.003
Time Based Checks
MalwareDRATzarus

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing. DRATzarus can also remotely shut down into sleep mode under specific conditions to evade
detection.

T1497.003
Time Based Checks
MalwareGoldMax

GoldMax has set an execution trigger date and time, stored as an ASCII Unix/Epoch time value.

T1497.003
Time Based Checks
MalwareDarkTortilla

DarkTortilla can implement the `kernel32.dll` Sleep function to delay execution for up to 300 seconds before implementing persistence or processing an addon package.

T1497.003
Time Based Checks
MalwareBisonal

Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing.

T1497.003
Time Based Checks
MalwareClambling

Clambling can wait 30 minutes before initiating contact with C2.

T1497.003
Time Based Checks
MalwareSVCReady

SVCReady can enter a sleep stage for 30 minutes to evade detection.

T1497.003
Time Based Checks
MalwareThiefQuest

ThiefQuest invokes time call to check the system's time, executes a sleep command, invokes a second time call, and then compares the time difference between the two time calls and the amount of time the system slept to identify the sandbox.

T1497.003
Time Based Checks
MalwareSaint Bot

Saint Bot has used the command `timeout 20` to pause the execution of its initial loader.

T1497.003
Time Based Checks
MalwareP8RAT

P8RAT has the ability to "sleep" for a specified time to evade detection.

T1497.003
Time Based Checks
MalwareBendyBear

BendyBear can check for analysis environments and signs of debugging using the Windows API kernel32!GetTickCountKernel32 call.

T1497.003
Time Based Checks
MalwareSodaMaster

SodaMaster has the ability to put itself to "sleep" for a specified time.

T1497.003
Time Based Checks
MalwareLiteDuke

LiteDuke can wait 30 seconds before executing additional code if security software is detected.

T1497.003
Time Based Checks
MalwareBazar

Bazar can use a timer to delay execution of core functionality.

T1497.003
Time Based Checks
MalwareHiddenFace

HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis.

T1497.003
Time Based Checks
MalwareHermeticWiper

HermeticWiper has the ability to receive a command parameter to sleep prior to carrying out destructive actions on a targeted host.

T1497.003
Time Based Checks
MalwareSUNBURST

SUNBURST remained dormant after initial access for a period of up to two weeks.

T1497.003
Time Based Checks
MalwareEvilBunny

EvilBunny has used time measurements from 3 different APIs before and after performing sleep operations to check and abort if the malware is running in a sandbox.

T1497.003
Time Based Checks
MalwareIPsec Helper

IPsec Helper will sleep for a random number of seconds, iterating 200 times over sleeps between one to three seconds, before continuing execution flow.

T1497.003
Time Based Checks
MalwareGoldenSpy

GoldenSpy's installer has delayed installation of GoldenSpy for two hours after it reaches a victim system.

T1497.003
Time Based Checks
MalwareGrimAgent

GrimAgent can sleep for 195 - 205 seconds after payload execution and before deleting its task.

T1497.003
Time Based Checks
MalwareClop

Clop has used the sleep command to avoid sandbox detection.

T1497.003
Time Based Checks
MalwareLokibot

Lokibot has performed a time-based anti-debug check before downloading its third stage.

T1497.003
Time Based Checks
MalwareEgregor

Egregor can perform a long sleep (greater than or equal to 3 minutes) to evade detection.

T1497.003
Time Based Checks
MalwaremetaMain

metaMain has delayed execution for five to six minutes during its persistence establishment process.

T1497.003
Time Based Checks
MalwareLunarWeb

LunarWeb can pause for a number of hours before entering its C2 communication loop.

T1497.003
Time Based Checks
MalwareXCSSET

Using the machine's local time, XCSSET waits 43200 seconds (12 hours) from the initial creation timestamp of a specific file, .report. After the elapsed time, XCSSET executes additional modules.

T1497.003
Time Based Checks
MalwareAppleJeus

AppleJeus has waited a specified time before downloading a second stage payload.

T1497.003
Time Based Checks
MalwareQakBot

The QakBot dropper can delay dropping the payload to evade detection.

T1497.003
Time Based Checks
MalwareStrifeWater

StrifeWater can modify its sleep time responses from the default of 20-22 seconds.

T1497.003
Time Based Checks
Toolevilginx2

evilginx2 has the ability to hide phishing lures for a set time to avoid scanning by sandboxes.

T1497.003
Time Based Checks
ToolBrute Ratel C4

Brute Ratel C4 can call `NtDelayExecution` to pause execution.

T1497.003
Time Based Checks
MalwareCanisterWorm

CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments.

T1497.003
Time Based Checks
MalwareBADFLICK

BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.