If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1497 - Virtualization/Sandbox Evasion.

site address: attack.mitre.org/techniques/T1497 redirected to: attack.mitre.org/techniques/T1497

site title: Virtualization/Sandbox Evasion, Technique T1497 - Enterprise MITRE ATT&CK®

Our opinion (on Friday 21 August 2026 2:24:12 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

virtualization, sandbox, evasion, procedure, examples, mitigations, detection, strategy, references, sub, techniques,

Text of the page (most frequently used words):
the (38), retrieved (33), and (26), analysis (22), sandbox (20), malware (19), 2022 (15), 2020 (14), #virtualization (14), has (14), may (13), anti (11), att (10), all (10), techniques (10), can (9), execution (9), for (9), t1497 (9), checks (9), 2015 (8), check (8), march (8), that (8), enterprise (7), detection (7), december (7), 2024 (7), 2021 (7), april (7), environment (7), evasion (7), use (6), september (6), october (6), june (6), with (6), 2026 (5), ics (5), mobile (5), none (5), 2025 (5), august (5), payloads (5), stealer (5), not (5), july (5), system (5), used (5), will (5), mitre (4), xloader (4), 2023 (4), february (4), strelastealer (4), 2019 (4), squirrelwaffle (4), new (4), redline (4), november (4), egregor (4), time (4), black (4), this (4), activity (4), artifacts (4), before (4), based (4), within (4), other (4), environments (4), version (4), adversaries (4), domains (3), software (3), cti (3), data (3), mitigations (3), defenses (3), sub (3), tactics (3), core (3), decryption (3), from (3), stonedrill (3), include (3), january (3), threat (3), raspberry (3), robin (3), bear (3), operation (3), spalax (3), metamorfo (3), icedid (3), hancitor (3), gelsemium (3), darkhotel (3), contagious (3), interview (3), carberp (3), bumblebee (3), basta (3), bisonal (3), bazar (3), payload (3), functions (3), discovery (3), calls (3), sleep (3), name (3), technique (3), code (3), methods (3), several (3), prevent (3), automated (3), sandboxes (3), running (3), ability (3), identify (3), random (3), number (3), virtual (3), additional (3), vme (3), corporation (2), are (2), resources (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), strategies (2), assets (2), matrices (2), objects (2), point (2), research (2), botnet (2), you (2), run (2), kumar (2), campaign (2), organizations (2), loader (2), delivering (2), cobalt (2), strike (2), unit (2), attacks (2), target (2), ukraine (2), banking (2), team (2), detections (2), russia (2), aka (2), victim (2), avast (2), executable (2), abuse (2), multiple (2), attack (2), ransomware (2), into (2), just (2), when (2), following (2), prior (2), commands (2), related (2), device (2), behavior (2), strategy (2), analytic (2), description (2), control (2), such (2), sandboxing (2), platforms (2), contains (2), saint (2), detect (2), virtualized (2), rtm (2), communication (2), real (2), only (2), pteranodon (2), during (2), compromised (2), mini (2), shai (2), hulud (2), attempts (2), kevin (2), traffic (2), macro (2), shape (2), object (2), found (2), exit (2), evade (2), ensure (2), machine (2), detects (2), cozycar (2), container (2), chopstick (2), various (2), perform (2), determine (2), agent (2), tesla (2), 003 (2), 002 (2), 001 (2), tools (2), also (2), user (2), avoid (2), behaviors (2), they (2), search (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, alexey, bukhteyev, raman, ladutska, find, any, formbook, encryption, fortgale, benjamin, chang, goutam, tripathy, pranay, chhaparwal, anmol, maurya, vishwa, thothathri, palo, alto, networks, large, scale, early, kaspersky, lab, 2017, shamoon, wipers, attacking, saudi, beyond, palazolo, qakbot, stone, gross, brett, spear, phishing, document, outsteel, downloader, saintbot, duncan, harbison, russian, language, malspam, pushing, redaman, splunk, cross, christopher, targets, telecom, governments, gamaredon, primitive, apt, group, actively, targeting, porolli, targeted, colombia, hunt, how, teampcp, python, toolkit, survives, takedown, firescale, github, own, account, erlich, abuser, hides, abusing, kayal, lyceum, reborn, counterintelligence, middle, east, kenefick, distributors, google, ppc, distribute, anubhav, jallepalli, 2016, chanitor, observed, using, approaches, dupuy, faou, nhs, digital, raas, successor, maze, cybleinc, deep, dive, its, activities, arunpreet, singh, clemens, kolbitsch, defeating, secure, labs, cozyduke, kirill, boychenko, another, wave, north, korean, drops, malicious, npm, packages, fireeye, apt28, window, cyber, espionage, operations, matrosov, rodionov, volkov, harley, 2012, win32, hole, stop, digging, merriman, trouerbach, isn, optimus, prime, but, still, transforming, unnoticed, delivery, mercer, years, play, cybereason, nocturnus, tricks, team9, development, cycles, jazi, agenttesla, variant, steals, wifi, credentials, falcone, wartell, ups, observations, cve, 3113, zero, days, pirpi, torello, guibernau, awareness, references, scripts, binaries, indicators, system_profiler, ioreg, kextstat, combined, delay, anomalous, launchd, an0129, enumerate, files, processes, sys, class, dmi, product_name, dmesg, lscpu, lspci, querying, hypervisor, interfaces, an0128, api, registry, keys, drivers, services, skipped, dlls, deployment, an0127, det0046, type, cannot, easily, mitigated, preventive, controls, since, features, utilize, decoy, command, configuration, circumvent, s1207, have, flow, obfuscation, excessively, long, blocks, mathematical, instructions, defeat, s1183, emulation, emulators, s0380, contained, hardcoded, list, addresses, block, belong, s1030, g1031, s0148, requires, consistently, server, fails, continue, s1240, fake, second, stage, initial, delivered, determines, s1130, s0147, actors, droppers, would, executing, host, c0005, evaded, applying, probability, gate, generates, which, trigger, wiper, functionality, set, outcome, met, even, match, parameters, geopolitical, s9043, embedded, vmdetect, exe, machines, beginning, s0455, interval, between, s1020, manipulated, keitaro, direction, filter, researcher, s0483, activedocument, lure, message, present, without, downloading, s0499, junk, generate, obscure, s0666, s0554, employed, strings, g0012, some, versions, being, executed, inside, known, s0046, requested, victims, disable, docker, thwart, isolation, infection, g1052, includes, runtime, s0023, removed, hooks, installing, trojan, bootkit, s0484, s1039, make, function, hinder, log, kernel32, beep, s1070, vmware, s0268, attempt, overload, sending, 1550, printf, s0534, s0331, procedure, examples, live, permalink, last, modified, created, deloitte, library, sunny, neo, contributors, linux, windows, macos, stealth, accomplish, checking, security, monitoring, sysinternals, wireshark, etc, associated, legitimate, help, timers, loops, operating, temporary, employ, means, changing, results, presence, indicative, adversary, alter, their, disengage, conceal, implant, dropping, secondary, information, learned, follow, home, open, join, mclean, hotel, location, details, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, about, get, started,


Text of the page (random words):
virtualization sandbox evasion technique t1497 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise virtualization sandbox evasion virtualization sandbox evasion sub techniques 3 id name t1497 001 system checks t1497 002 user activity based checks t1497 003 time based checks adversaries may employ various means to detect and avoid virtualization and analysis environments this may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment vme or sandbox if the adversary detects a vme they may alter their malware to disengage from the victim or conceal the core functions of the implant they may also search for vme artifacts before dropping secondary or additional payloads adversaries may use the information learned from virtualization sandbox evasion during automated discovery to shape follow on behaviors 1 adversaries may use several methods to accomplish virtualization sandbox evasion such as checking for security monitoring tools e g sysinternals wireshark etc or other system artifacts associated with analysis or virtualization adversaries may also check for legitimate user activity to help determine if it is in an analysis environment additional methods include use of sleep timers or loops within malware code to avoid operating within a temporary sandbox 2 id t1497 sub techniques t1497 001 t1497 002 t1497 003 ⓘ tactics stealth discovery ⓘ platforms linux windows macos contributors deloitte threat library team sunny neo version 2 0 created 17 april 2019 last modified 12 may 2026 version permalink live version procedure examples id name description s0331 agent tesla agent tesla has the ability to perform anti sandboxing and anti virtualization checks 3 s0534 bazar bazar can attempt to overload sandbox analysis by sending 1550 calls to printf 4 s0268 bisonal bisonal can check to determine if the compromised system is running on vmware 5 s1070 black basta black basta can make a random number of calls to the kernel32 beep function to hinder log analysis 6 s1039 bumblebee bumblebee has the ability to perform anti virtualization checks 7 s0484 carberp carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software 8 s0023 chopstick chopstick includes runtime checks to identify an analysis environment and prevent execution on it 9 g1052 contagious interview contagious interview has requested victims to disable docker and other container environments in attempts to thwart container isolation and ensure device infection 10 s0046 cozycar some versions of cozycar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment if it detects that it is it will exit 11 g0012 darkhotel darkhotel malware has employed just in time decryption of strings to evade sandbox detection 12 s0554 egregor egregor has used multiple anti analysis and anti sandbox techniques to prevent automated analysis by sandboxes 13 14 s0666 gelsemium gelsemium can use junk code to generate random activity to obscure malware behavior 15 s0499 hancitor hancitor has used a macro to check that an activedocument shape object in the lure message is present if this object is not found the macro will exit without downloading additional payloads 16 s0483 icedid icedid has manipulated keitaro traffic direction system to filter researcher and sandbox traffic 17 s1020 kevin kevin can sleep for a time interval between c2 communication attempts 18 s0455 metamorfo metamorfo has embedded a vmdetect exe executable to identify virtual machines at the beginning of execution 19 s9043 mini shai hulud mini shai hulud has evaded sandbox detection by applying a 1 in 6 probability gate that generates a random number which will only trigger the wiper functionality when the set number outcome is met even in environments that match parameters of a geopolitical target 20 c0005 operation spalax during operation spalax the threat actors used droppers that would run anti analysis checks before executing malware on a compromised host 21 s0147 pteranodon pteranodon has the ability to use anti detection functions to identify sandbox environments 22 s1130 raspberry robin raspberry robin contains real and fake second stage payloads following initial execution with the real payload only delivered if the malware determines it is not running in a virtualized environment 23 s1240 redline stealer redline stealer has an anti sandbox technique that requires the malware to consistently check with the c2 server if the communication fails redline stealer will not continue execution 24 s0148 rtm rtm can detect if it is running within a sandbox or other virtualized analysis environment 25 g1031 saint bear saint bear contains several anti analysis and anti virtualization checks 26 s1030 squirrelwaffle squirrelwaffle has contained a hardcoded list of ip addresses to block that belong to sandboxes and analysis platforms 27 28 s0380 stonedrill stonedrill has used several anti emulation techniques to prevent automated analysis by emulators or sandboxes 29 s1183 strelastealer strelastealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods 30 31 s1207 xloader xloader can utilize decoy command and control domains within the malware configuration to circumvent sandbox analysis 32 33 mitigations this type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features detection strategy id name analytic id analytic description det0046 detection strategy for t1497 virtualization sandbox evasion an0127 execution of discovery commands or api calls for virtualization artifacts e g registry keys device drivers services sleep skipped execution behavior or sandbox evasion dlls before payload deployment an0128 execution of commands to enumerate virtualization related files or processes e g sys class dmi id product_name dmesg lscpu lspci or querying hypervisor interfaces prior to malware execution an0129 execution of scripts or binaries that check for virtualization indicators e g system_profiler ioreg l kextstat combined with delay functions or anomalous launchd activity references torello a guibernau f n d environment awareness retrieved september 13 2024 falcone r wartell r 2015 july 27 ups observations on cve 2015 3113 prior zero days and the pirpi payload retrieved april 23 2019 jazi h 2020 april 16 new agenttesla variant steals wifi credentials retrieved may 19 2020 cybereason nocturnus 2020 july 16 a bazar of tricks following team9 s development cycles retrieved november 18 2020 mercer w et al 2020 march 5 bisonal 10 years of play retrieved january 26 2022 check point 2022 october 20 black basta and the unnoticed delivery retrieved march 8 2023 merriman k and trouerbach p 2022 april 28 this isn t optimus prime s bumblebee but it s still transforming retrieved august 22 2022 matrosov a rodionov e volkov d harley d 2012 march 2 win32 carberp when you re in a black hole stop digging retrieved july 15 2020 fireeye 2015 apt28 a window into russia s cyber espionage operations retrieved august 19 2015 kirill boychenko 2025 june 25 another wave north korean contagious interview campaign drops 35 new malicious npm packages retrieved october 19 2025 f secure labs 2015 april 22 cozyduke malware analysis retrieved december 10 2015 arunpreet singh clemens kolbitsch 2015 november 5 defeating darkhotel just in time decryption retrieved april 15 2021 cybleinc 2020 october 31 egregor ransomware a deep dive into its activities and techniques retrieved december 29 2020 nhs digital 2020 november 26 egregor ransomware the raas successor to maze retrieved december 29 2020 dupuy t and faou m 2021 june gelsemium retrieved november 30 2021 anubhav a jallepalli d 2016 september 23 hancitor aka chanitor observed using multiple attack approaches retrieved august 13 2020 kenefick i 2022 december 23 icedid botnet distributors abuse google ppc to distribute malware retrieved july 24 2024 kayal a et al 2021 october lyceum reborn counterintelligence in the middle east retrieved june 14 2022 erlich c 2020 april 3 the avast abuser metamorfo banking malware hides by abusing avast executable retrieved may 26 2020 hunt io 2026 may 14 how teampcp s python toolkit survives a c2 takedown firescale github and the victim s own account retrieved july 16 2026 m porolli 2021 january 21 operation spalax targeted malware attacks in colombia retrieved september 16 2022 unit 42 2022 february 3 russia s gamaredon aka primitive bear apt group actively targeting ukraine retrieved february 21 2022 christopher so 2022 december 20 raspberry robin malware targets telecom governments retrieved may 17 2024 splunk threat research team 2023 june 1 do not cross the redline stealer detections and analysis retrieved september 17 2025 duncan b harbison m 2019 january 23 russian language malspam pushing redaman banking malware retrieved june 16 2020 unit 42 2022 february 25 spear phishing attacks target organizations in ukraine payloads include the document stealer outsteel and the downloader saintbot retrieved june 9 2022 kumar a stone gross brett 2021 september 28 squirrelwaffle new loader delivering cobalt strike retrieved august 9 2022 palazolo g 2021 october 7 squirrelwaffle new malware loader delivering cobalt strike and qakbot retrieved august 9 2022 kaspersky lab 2017 march 7 from shamoon to stonedrill wipers attacking saudi organizations and beyond retrieved march 14 2019 benjamin chang goutam tripathy pranay kumar chhaparwal anmol maurya vishwa thothathri palo alto networks 2024 march 22 large scale strelastealer campaign in early 2024 retrieved december 31 2024 fortgale 2023 september 18 strelastealer malware analysis retrieved december 31 2024 any run 2023 february 28 xloader formbook encryption analysis and malware decryption retrieved march 11 2025 alexey bukhteyev raman ladutska check point research 2022 may 31 xloader botnet find me if you can retrieved march 11 2025 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 78 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-78


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1497
X-GitHub-Request-Id 8ECE:15BD:45FEC9:46D66A:6A87B6CA
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Fri, 21 Aug 2026 02:24:11 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290033-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787279052.550645,VS0,VE89
Vary Accept-Encoding
X-Fastly-Request-ID 96e463f32ea10e386f3e6229e1c6807ae661bc6a
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1497/
access-control-allow-origin *
expires Fri, 21 Aug 2026 02:34:11 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 0FF2:2A0E2:13C1F9D:13E713C:6A87B6CB
x-github-edge-region fra
accept-ranges bytes
age 0
date Fri, 21 Aug 2026 02:24:11 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290042-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787279052.666274,VS0,VE100
vary Accept-Encoding
x-fastly-request-id 7d24b5fa9013e889b0671edadbe7e777c38ae9e4
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-15021
expires Fri, 21 Aug 2026 01:17:17 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 4ADA:321A:11EF22E:120F095:6A87A4C4
x-github-edge-region fra
accept-ranges bytes
age 0
date Fri, 21 Aug 2026 02:24:11 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290042-RTM
x-cache HIT
x-cache-hits 0
x-timer S1787279052.773954,VS0,VE113
vary Accept-Encoding
x-fastly-request-id 004be5e86f64928e8773bf31978d69c592da049c
content-length 14356

Meta Tags

title="Virtualization/Sandbox Evasion, Technique T1497 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size14356
load time (s)0.569033
redirect count2
speed download25230
server IP 185.199.110.153
* all occurrences of the string "http://" have been changed to "htt???/"