ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1497.001
System Checks
MalwareAstaroth

Astaroth can check for Windows product ID's used by sandboxes and usernames and disk serial numbers associated with analyst environments.

T1497.001
System Checks
MalwareQakBot

QakBot can check the compromised host for the presence of multiple executables associated with analysis tools and halt execution if any are found.

T1497.001
System Checks
MalwareDenis

Denis ran multiple system checks, looking for processor and register characteristics, to evade emulation and analysis.

T1497.001
System Checks
ToolCSPY Downloader

CSPY Downloader can search loaded modules, PEB structure, file paths, Registry keys, and memory to determine if it is being debugged or running in a virtual environment.

T1497.001
System Checks
ToolAsyncRAT

AsyncRAT can identify strings such as Virtual, vmware, or VirtualBox to detect virtualized environments.

T1497.001
System Checks
ToolRemcos

Remcos searches for Sandboxie and VMware on the system.

T1497.001
System Checks
ToolPupy

Pupy has a module that checks a number of indicators on the system to determine if its running on a virtual machine.

T1497.001
System Checks
MalwareMini Shai-Hulud

Mini Shai-Hulud has evaded execution in virtual environments and sandboxes through checking system information to include the number of CPUs and exiting at times when there were less than four and other times when there were less than two CPUs.

T1497.002
User Activity Based Checks
MalwareSpark

Spark has used a splash screen to check whether an user actively clicks on the screen before running malicious code.

T1497.002
User Activity Based Checks
MalwareROAMINGHOUSE

ROAMINGHOUSE can check for specific mouse movements and user activity before initiating malicious activity.

T1497.002
User Activity Based Checks
MalwareTONESHELL

TONESHELL has leveraged `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle.

T1497.002
User Activity Based Checks
MalwareOkrum

Okrum loader only executes the payload after the left mouse button has been pressed at least three times, in order to avoid being executed within virtualized or emulated environments.

T1497.002
User Activity Based Checks
MalwareCobalt Strike

The Cobalt Strike loader can use the `MessageBoxA` API to prompt for user interaction as an anti-sandbox measure.

T1497.003
Time Based Checks
MalwareTrickBot

TrickBot has used printf and file I/O loops to delay process execution as part of API hammering.

T1497.003
Time Based Checks
MalwareBumblebee

Bumblebee has the ability to set a hardcoded and randomized sleep interval.

T1497.003
Time Based Checks
MalwareUrsnif

Ursnif has used a 30 minute delay after execution to evade sandbox monitoring tools.

T1497.003
Time Based Checks
MalwareRansomHub

RansomHub can sleep for a set number of minutes before beginning execution.

T1497.003
Time Based Checks
MalwareHavoc

The Havoc demon agent can be set to sleep for a specified time.

T1497.003
Time Based Checks
MalwarePony

Pony has delayed execution using a built-in function to avoid detection and analysis.

T1497.003
Time Based Checks
MalwareCrimson

Crimson can determine when it has been installed on a host for at least 15 days before downloading the final payload.

T1497.003
Time Based Checks
MalwareTomiris

Tomiris has the ability to sleep for at least nine minutes to evade sandbox-based analysis systems.

T1497.003
Time Based Checks
MalwareGootloader

Gootloader can designate a sleep period of more than 22 seconds between stages of infection.

T1497.003
Time Based Checks
MalwareSnip3

Snip3 can execute `WScript.Sleep` to delay execution of its second stage.

T1497.003
Time Based Checks
MalwareGuLoader

GuLoader has the ability to perform anti-debugging based on time checks, API calls, and CPUID.

T1497.003
Time Based Checks
MalwareWhisperGate

WhisperGate can pause for 20 seconds to bypass antivirus solutions.

T1497.003
Time Based Checks
MalwareOkrum

Okrum's loader can detect presence of an emulator by using two calls to GetTickCount API, and checking whether the time has been accelerated.

T1497.003
Time Based Checks
MalwareRaindrop

After initial installation, Raindrop runs a computation to delay execution.

T1497.003
Time Based Checks
MalwareFatDuke

FatDuke can turn itself on or off at random intervals.

T1497.003
Time Based Checks
MalwareDRATzarus

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing. DRATzarus can also remotely shut down into sleep mode under specific conditions to evade
detection.

T1497.003
Time Based Checks
MalwareGoldMax

GoldMax has set an execution trigger date and time, stored as an ASCII Unix/Epoch time value.

T1497.003
Time Based Checks
MalwareDarkTortilla

DarkTortilla can implement the `kernel32.dll` Sleep function to delay execution for up to 300 seconds before implementing persistence or processing an addon package.

T1497.003
Time Based Checks
MalwareBisonal

Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing.

T1497.003
Time Based Checks
MalwareClambling

Clambling can wait 30 minutes before initiating contact with C2.

T1497.003
Time Based Checks
MalwareSVCReady

SVCReady can enter a sleep stage for 30 minutes to evade detection.

T1497.003
Time Based Checks
MalwareThiefQuest

ThiefQuest invokes time call to check the system's time, executes a sleep command, invokes a second time call, and then compares the time difference between the two time calls and the amount of time the system slept to identify the sandbox.

T1497.003
Time Based Checks
MalwareSaint Bot

Saint Bot has used the command `timeout 20` to pause the execution of its initial loader.

T1497.003
Time Based Checks
MalwareP8RAT

P8RAT has the ability to "sleep" for a specified time to evade detection.

T1497.003
Time Based Checks
MalwareBendyBear

BendyBear can check for analysis environments and signs of debugging using the Windows API kernel32!GetTickCountKernel32 call.

T1497.003
Time Based Checks
MalwareSodaMaster

SodaMaster has the ability to put itself to "sleep" for a specified time.

T1497.003
Time Based Checks
MalwareLiteDuke

LiteDuke can wait 30 seconds before executing additional code if security software is detected.

T1497.003
Time Based Checks
MalwareBazar

Bazar can use a timer to delay execution of core functionality.

T1497.003
Time Based Checks
MalwareHiddenFace

HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis.

T1497.003
Time Based Checks
MalwareHermeticWiper

HermeticWiper has the ability to receive a command parameter to sleep prior to carrying out destructive actions on a targeted host.

T1497.003
Time Based Checks
MalwareSUNBURST

SUNBURST remained dormant after initial access for a period of up to two weeks.

T1497.003
Time Based Checks
MalwareEvilBunny

EvilBunny has used time measurements from 3 different APIs before and after performing sleep operations to check and abort if the malware is running in a sandbox.

T1497.003
Time Based Checks
MalwareIPsec Helper

IPsec Helper will sleep for a random number of seconds, iterating 200 times over sleeps between one to three seconds, before continuing execution flow.

T1497.003
Time Based Checks
MalwareGoldenSpy

GoldenSpy's installer has delayed installation of GoldenSpy for two hours after it reaches a victim system.

T1497.003
Time Based Checks
MalwareGrimAgent

GrimAgent can sleep for 195 - 205 seconds after payload execution and before deleting its task.

T1497.003
Time Based Checks
MalwareClop

Clop has used the sleep command to avoid sandbox detection.

T1497.003
Time Based Checks
MalwareLokibot

Lokibot has performed a time-based anti-debug check before downloading its third stage.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.