Case C660D3 · Malware & intel · L4 Advanced
Sandbox and anti-analysis evasion
Practise as: Explain it · Interview
Interview questionA sample does nothing in your sandbox and exits cleanly. How does malware detect analysis, and how do you get it to detonate?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- VM checks: CPUID hypervisor bit, VMware/VirtualBox MAC OUIs, drivers, registry keys, low core count, RAM or disk size
- Human checks: low uptime, few recent files, no mouse movement, empty browser history; geofencing by locale or keyboard
- Timing tricks: long sleeps beat sandbox timeouts; RDTSC or GetTickCount deltas detect sleep skipping and debuggers
- Debugger checks: IsDebuggerPresent, PEB BeingDebugged/NtGlobalFlag, NtQueryInformationProcess, hardware breakpoints
- Counter: harden or bare-metal VMs, fake C2 with FakeNet-NG/INetSim, patch checks in x64dbg, or unpack and analyse statically
If the interviewer pushes back
- The loader only fetches stage 2 if the victim's domain name matches. How do you analyse it without that environment?
- Why is a sample that evades your sandbox still a detection opportunity, and what would you alert on?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.