FORENSIA

ATT&CK · T1497

Virtualization/Sandbox Evasion

Tactics: stealth, discovery

About

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors. Adversaries may use several methods to accomplish Virtualization/Sandbox Evasion such as checking for security monitoring tools (e.g., Sysinternals, Wireshark, etc.) or other system artifacts associated with analysis or virtualization. Adversaries may also check for legitimate user activity to help determine if it is in an analysis environment. Additional methods include use of sleep timers or loops within malware code to avoid operating within a temporary sandbox.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

3 known groups

Software

22 malware/tools implement this

CHOPSTICKCozyCarPteranodonRTMBisonalAgent TeslaStoneDrillMetamorfoIcedIDCarberpHancitorBazarEgregorGelsemiumKevinSquirrelwaffleBumblebeeBlack BastaRaspberry RobinStrelaStealerXLoaderRedLine Stealer

Corpus indicators tagged with this technique

5,325 indicators in the corpus carry T1497.

IndicatorTypeFamilySevSrc
cve-2017-17215cve852
cve-2018-8007cve851
cve-2024-1781cve851
606966a9ec33765baedf63331595d1168f2a596fhash803
185b7a487316454da04e9cc0fe6eb370bb2955cf6096fe3e8c02c46f8989ba37hashphishing802
2af0a6135df3502a7f6de4d2de6db73bhash803
3a8f6454927b8993aded75de0de2bd00hashphishing802
5d253cc263851ec68c0a988bf86afbb3e9f0b491hashcryptojacking802
b6a77b7892ef22d6afd91eb980a3f3d8hashcryptojacking802
22b07d2af98bb180474c33d93861124bbdf9b5dd7e42a8bddc654310469a9a2chash803
0d681bd160db1b1df5db321a6d2dd9ae81b2609bhash801
e84b1e2c432b2394c403b524b8361ffa9923a022eb05215f1dc811bc167c3c5ehashcryptojacking802
a14bed1c46ba7406d5240e979251ccd394dfe3b5hashcryptojacking802
1fc5e6458316277fae8272cbe9f3dfc86b681635hashcryptojacking802
a37f6403fbf28fa0b48863287f4c5a5dhashcryptojacking802
d7d2f0ee187549f3f4a114d716be12521fbf62d6d26e2ac23d2a32d521d08fd8sha256phishing801
adcd15f3d6b87f84d106ea426fa824fd20c9d64f6d199ce92580884290785f30sha256phishing801
7b7981c99d59595fe15377df84695bb72ce0b85560a3935f930657b2d162e5efsha256phishing801
93b3d3925ccc201ab0f16017153a79ef05b8f5c2hashcryptojacking802
579a82dde4425d95e20a22171be0a37702c833fdca6e5e04f69099a025863136hashcryptojacking802
462af0a3a9094d44c30cc65544ec1171a62365cff09e67f5e87e061a3d604bd0hashcryptojacking802
c5a53c02d531c5e46f9cc2fc0afbb88dhashcryptojacking802
50eda29bfbeeb8b0429718447725016ahashcryptojacking802
89930bd18e0f9c9c98dfb1662cb87aa98348e87164ab62b1f39e86ebf2ce24cbhashcryptojacking802
b5da6ffa5f85aa5016fbc02a3122361c85d21192c45df9544099d13e6ff84c36hashcryptojacking802
d42aecf76fb1531cd5b7139e669910b2fd82a90b7e11448128e226775bf5d42ehashcryptojacking802
bd46890121106b43f0c01ab82629400chashcryptojacking802
ce62d1b6116f34f9ba815db1e2016d2ahashcryptojacking802
41f581f7d2c09ab0edfea850b9db506fhashcryptojacking802
69315b7a1c4bf5ee56cba1de29d1761ehashcryptojacking802

Showing the top 30 by severity of 5,325.