Time Based Checks

T1497.003

Sub-technique of T1497 Virtualization/Sandbox Evasion.View on attack.mitre.org

About this technique

Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time. This may include enumerating time-based properties, such as uptime or the system clock.

Adversaries may use calls like `GetTickCount` and `GetSystemTimeAsFileTime` to discover if they are operating within a virtual machine or sandbox, or may be able to identify a sandbox accelerating time by sampling and calculating the expected value for an environment's timestamp before and after execution of a sleep function.

Detection rules3

Rules on DetectionCode tagged with T1497.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk3

RuleTypeRiskData source
Ping Sleep Batch CommandAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Windows Time Based EvasionTTPNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Windows Time Based Evasion via Choice ExecAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups0

None recorded.

Software48

Show 24 more

Campaigns1

Procedure examples49

Software48

Used byProcedure example
MalwareAppleJeus

AppleJeus has waited a specified time before downloading a second stage payload.

MalwareBADFLICK

BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes.

MalwareBazar

Bazar can use a timer to delay execution of core functionality.

MalwareBendyBear

BendyBear can check for analysis environments and signs of debugging using the Windows API kernel32!GetTickCountKernel32 call.

MalwareBisonal

Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing.

ToolBrute Ratel C4

Brute Ratel C4 can call `NtDelayExecution` to pause execution.

MalwareBumblebee

Bumblebee has the ability to set a hardcoded and randomized sleep interval.

MalwareCanisterWorm

CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments.

View all 48 software examples

Campaigns1

Used byProcedure example
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services.

References1

  1. ISACA Malware Tricks Open source
    Kolbitsch, C. (2017, November 1). Evasive Malware Tricks: How Malware Evades Detection by Sandboxes. Retrieved March 30, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.