Open cardosec

Case C660D3 · Malware & intel · L4 Advanced

Sandbox and anti-analysis evasion

Practise as: Explain it · Interview

Interview questionA sample does nothing in your sandbox and exits cleanly. How does malware detect analysis, and how do you get it to detonate?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. VM checks: CPUID hypervisor bit, VMware/VirtualBox MAC OUIs, drivers, registry keys, low core count, RAM or disk size
  2. Human checks: low uptime, few recent files, no mouse movement, empty browser history; geofencing by locale or keyboard
  3. Timing tricks: long sleeps beat sandbox timeouts; RDTSC or GetTickCount deltas detect sleep skipping and debuggers
  4. Debugger checks: IsDebuggerPresent, PEB BeingDebugged/NtGlobalFlag, NtQueryInformationProcess, hardware breakpoints
  5. Counter: harden or bare-metal VMs, fake C2 with FakeNet-NG/INetSim, patch checks in x64dbg, or unpack and analyse statically

If the interviewer pushes back

  • The loader only fetches stage 2 if the victim's domain name matches. How do you analyse it without that environment?
  • Why is a sample that evades your sandbox still a detection opportunity, and what would you alert on?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.