Sub-technique of T1497 Virtualization/Sandbox Evasion.View on attack.mitre.org
Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time. This may include enumerating time-based properties, such as uptime or the system clock.
Adversaries may use calls like `GetTickCount` and `GetSystemTimeAsFileTime` to discover if they are operating within a virtual machine or sandbox, or may be able to identify a sandbox accelerating time by sampling and calculating the expected value for an environment's timestamp before and after execution of a sleep function.
Rules on DetectionCode tagged with T1497.003.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Ping Sleep Batch Command | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Time Based Evasion | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Time Based Evasion via Choice Exec | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareAppleJeus | AppleJeus has waited a specified time before downloading a second stage payload. |
| MalwareBADFLICK | BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes. |
| MalwareBazar | Bazar can use a timer to delay execution of core functionality. |
| MalwareBendyBear | BendyBear can check for analysis environments and signs of debugging using the Windows API |
| MalwareBisonal | Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing. |
| ToolBrute Ratel C4 | Brute Ratel C4 can call `NtDelayExecution` to pause execution. |
| MalwareBumblebee | Bumblebee has the ability to set a hardcoded and randomized sleep interval. |
| MalwareCanisterWorm | CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.