Real-world descriptions of how a group, tool or campaign used a technique.
48 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1497.003 Time Based Checks |
MalwareTrickBot | TrickBot has used |
| T1497.003 Time Based Checks |
MalwareBumblebee | Bumblebee has the ability to set a hardcoded and randomized sleep interval. |
| T1497.003 Time Based Checks |
MalwareUrsnif | Ursnif has used a 30 minute delay after execution to evade sandbox monitoring tools. |
| T1497.003 Time Based Checks |
MalwareRansomHub | RansomHub can sleep for a set number of minutes before beginning execution. |
| T1497.003 Time Based Checks |
MalwareHavoc | The Havoc demon agent can be set to sleep for a specified time. |
| T1497.003 Time Based Checks |
MalwarePony | Pony has delayed execution using a built-in function to avoid detection and analysis. |
| T1497.003 Time Based Checks |
MalwareCrimson | Crimson can determine when it has been installed on a host for at least 15 days before downloading the final payload. |
| T1497.003 Time Based Checks |
MalwareTomiris | Tomiris has the ability to sleep for at least nine minutes to evade sandbox-based analysis systems. |
| T1497.003 Time Based Checks |
MalwareGootloader | Gootloader can designate a sleep period of more than 22 seconds between stages of infection. |
| T1497.003 Time Based Checks |
MalwareSnip3 | Snip3 can execute `WScript.Sleep` to delay execution of its second stage. |
| T1497.003 Time Based Checks |
MalwareGuLoader | GuLoader has the ability to perform anti-debugging based on time checks, API calls, and CPUID. |
| T1497.003 Time Based Checks |
MalwareWhisperGate | WhisperGate can pause for 20 seconds to bypass antivirus solutions. |
| T1497.003 Time Based Checks |
MalwareOkrum | Okrum's loader can detect presence of an emulator by using two calls to GetTickCount API, and checking whether the time has been accelerated. |
| T1497.003 Time Based Checks |
MalwareRaindrop | After initial installation, Raindrop runs a computation to delay execution. |
| T1497.003 Time Based Checks |
MalwareFatDuke | FatDuke can turn itself on or off at random intervals. |
| T1497.003 Time Based Checks |
MalwareDRATzarus | DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing. DRATzarus can also remotely shut down into sleep mode under specific conditions to evade |
| T1497.003 Time Based Checks |
MalwareGoldMax | GoldMax has set an execution trigger date and time, stored as an ASCII Unix/Epoch time value. |
| T1497.003 Time Based Checks |
MalwareDarkTortilla | DarkTortilla can implement the `kernel32.dll` Sleep function to delay execution for up to 300 seconds before implementing persistence or processing an addon package. |
| T1497.003 Time Based Checks |
MalwareBisonal | Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing. |
| T1497.003 Time Based Checks |
MalwareClambling | Clambling can wait 30 minutes before initiating contact with C2. |
| T1497.003 Time Based Checks |
MalwareSVCReady | SVCReady can enter a sleep stage for 30 minutes to evade detection. |
| T1497.003 Time Based Checks |
MalwareThiefQuest | ThiefQuest invokes |
| T1497.003 Time Based Checks |
MalwareSaint Bot | Saint Bot has used the command `timeout 20` to pause the execution of its initial loader. |
| T1497.003 Time Based Checks |
MalwareP8RAT | P8RAT has the ability to "sleep" for a specified time to evade detection. |
| T1497.003 Time Based Checks |
MalwareBendyBear | BendyBear can check for analysis environments and signs of debugging using the Windows API |
| T1497.003 Time Based Checks |
MalwareSodaMaster | SodaMaster has the ability to put itself to "sleep" for a specified time. |
| T1497.003 Time Based Checks |
MalwareLiteDuke | LiteDuke can wait 30 seconds before executing additional code if security software is detected. |
| T1497.003 Time Based Checks |
MalwareBazar | Bazar can use a timer to delay execution of core functionality. |
| T1497.003 Time Based Checks |
MalwareHiddenFace | HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis. |
| T1497.003 Time Based Checks |
MalwareHermeticWiper | HermeticWiper has the ability to receive a command parameter to sleep prior to carrying out destructive actions on a targeted host. |
| T1497.003 Time Based Checks |
MalwareSUNBURST | SUNBURST remained dormant after initial access for a period of up to two weeks. |
| T1497.003 Time Based Checks |
MalwareEvilBunny | EvilBunny has used time measurements from 3 different APIs before and after performing sleep operations to check and abort if the malware is running in a sandbox. |
| T1497.003 Time Based Checks |
MalwareIPsec Helper | IPsec Helper will sleep for a random number of seconds, iterating 200 times over sleeps between one to three seconds, before continuing execution flow. |
| T1497.003 Time Based Checks |
MalwareGoldenSpy | GoldenSpy's installer has delayed installation of GoldenSpy for two hours after it reaches a victim system. |
| T1497.003 Time Based Checks |
MalwareGrimAgent | GrimAgent can sleep for 195 - 205 seconds after payload execution and before deleting its task. |
| T1497.003 Time Based Checks |
MalwareClop | Clop has used the |
| T1497.003 Time Based Checks |
MalwareLokibot | Lokibot has performed a time-based anti-debug check before downloading its third stage. |
| T1497.003 Time Based Checks |
MalwareEgregor | Egregor can perform a long sleep (greater than or equal to 3 minutes) to evade detection. |
| T1497.003 Time Based Checks |
MalwaremetaMain | metaMain has delayed execution for five to six minutes during its persistence establishment process. |
| T1497.003 Time Based Checks |
MalwareLunarWeb | LunarWeb can pause for a number of hours before entering its C2 communication loop. |
| T1497.003 Time Based Checks |
MalwareXCSSET | Using the machine's local time, XCSSET waits 43200 seconds (12 hours) from the initial creation timestamp of a specific file, |
| T1497.003 Time Based Checks |
MalwareAppleJeus | AppleJeus has waited a specified time before downloading a second stage payload. |
| T1497.003 Time Based Checks |
MalwareQakBot | The QakBot dropper can delay dropping the payload to evade detection. |
| T1497.003 Time Based Checks |
MalwareStrifeWater | StrifeWater can modify its sleep time responses from the default of 20-22 seconds. |
| T1497.003 Time Based Checks |
Toolevilginx2 | evilginx2 has the ability to hide phishing lures for a set time to avoid scanning by sandboxes. |
| T1497.003 Time Based Checks |
ToolBrute Ratel C4 | Brute Ratel C4 can call `NtDelayExecution` to pause execution. |
| T1497.003 Time Based Checks |
MalwareCanisterWorm | CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments. |
| T1497.003 Time Based Checks |
MalwareBADFLICK | BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.