T1497.003 Time Based Checks — ATT&CK Technique
Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time. This may include enumerating time-based properties, such as uptime or the system clock. Adversaries may use calls like `GetTickCount` and `GetSystemTimeAsFileTime` to discover if they are operating within a virtual machine or sandbox, or may be able to identify a sandbox accelerating time by sampling and calculating the expected value for an environment's timestamp before and after execution of a sleep function.
Detection coverage (3)
Malware using this technique
- TrickBot
- Bumblebee
- Ursnif
- RansomHub
- Havoc
- Pony
- Crimson
- Tomiris
- Gootloader
- Snip3
- GuLoader
- WhisperGate
- Okrum
- Raindrop
- FatDuke
- DRATzarus
- IPsec Helper
- GoldMax
- DarkTortilla
- Bisonal
- Clambling
- SUNBURST
- EvilBunny
- SVCReady
- ThiefQuest
- Saint Bot
- P8RAT
- BendyBear
- SodaMaster
- LiteDuke
- Bazar
- HiddenFace
- HermeticWiper
- GoldenSpy
- GrimAgent
- Clop
- Lokibot
- Egregor
- metaMain
- LunarWeb
- XCSSET
- AppleJeus
- QakBot
- StrifeWater
- evilginx2
- CanisterWorm
- Brute Ratel C4
- BADFLICK