Virtualization/Sandbox Evasion

T1497

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Adversaries may use several methods to accomplish Virtualization/Sandbox Evasion such as checking for security monitoring tools (e.g., Sysinternals, Wireshark, etc.) or other system artifacts associated with analysis or virtualization. Adversaries may also check for legitimate user activity to help determine if it is in an analysis environment. Additional methods include use of sleep timers or loops within malware code to avoid operating within a temporary sandbox.

Detection rules13

Rules on DetectionCode tagged with T1497 or one of its sub-techniques.

Sigma3

RuleLevelLog sourceTechnique
Powershell Detect Virtualization Environmentmediumwindows / ps_scriptT1497.001
System Information Discovery Using System_Profilermediummacos / process_creationT1497.001
System Information Discovery Via Sysctl - MacOSmediummacos / process_creationT1497.001

Splunk10

RuleTypeRiskData sourceTechnique
Headless Browser UsageAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1497
Ping Sleep Batch CommandAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2T1497.003
Windows Chromium Browser Launched with Small Window SizeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1497
Windows Chromium Browser No Security Sandbox ProcessTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1497
Windows Chromium Browser with Custom User Data DirectoryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1497
Windows Chromium process Launched with Disable Popup BlockingAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1497
Windows Chromium Process Launched with Logging DisabledAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1497
Windows Chromium Process with Disabled ExtensionsAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1497
Windows Time Based EvasionTTPNULLSysmon EventID 1, CrowdStrike ProcessRollup2T1497.003
Windows Time Based Evasion via Choice ExecAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1497.003

Sub-techniques3

IDNameExamples
T1497.001System Checks70
T1497.002User Activity Based Checks7
T1497.003Time Based Checks49

Groups3

Software23

Campaigns1

Procedure examples27

Groups3

Used byProcedure example
GroupContagious Interview

Contagious Interview has requested victims to disable Docker and other container environments in attempts to thwart container isolation and ensure device infection.

GroupDarkhotel

Darkhotel malware has employed just-in-time decryption of strings to evade sandbox detection.

GroupSaint Bear

Saint Bear contains several anti-analysis and anti-virtualization checks.

Software23

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks.

MalwareBazar

Bazar can attempt to overload sandbox analysis by sending 1550 calls to printf.

MalwareBisonal

Bisonal can check to determine if the compromised system is running on VMware.

MalwareBlack Basta

Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis.

MalwareBumblebee

Bumblebee has the ability to perform anti-virtualization checks.

MalwareCarberp

Carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software.

MalwareCHOPSTICK

CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it.

MalwareCozyCar

Some versions of CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. If it detects that it is, it will exit.

View all 23 software examples

Campaigns1

Used byProcedure example
CampaignOperation Spalax

During Operation Spalax, the threat actors used droppers that would run anti-analysis checks before executing malware on a compromised host.

References2

  1. Deloitte Environment Awareness Open source
    Torello, A. & Guibernau, F. (n.d.). Environment Awareness. Retrieved September 13, 2024.
  2. Unit 42 Pirpi July 2015 Open source
    Falcone, R., Wartell, R.. (2015, July 27). UPS: Observations on CVE-2015-3113, Prior Zero-Days and the Pirpi Payload. Retrieved April 23, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.