logo

Enumerating Anti-Sandboxing Techniques

ID: 31a5f6d2-030d-558b-b748-3bc8a89efb5b

STIX ID: report--31a5f6d2-030d-558b-b748-3bc8a89efb5b

Feed Name: TrustedSec blog

Threat Score
20/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This research report details creating benign Windows binaries that implement various anti-sandbox checks and submitting them to VirusTotal, Hybrid Analysis, and MetaDefender (June 2018) to measure which sandbox-evasion techniques are most likely to be detected. Results show that sleep delays, AV/process-name checks, and disk-size checks commonly trigger detections, while checks like domain membership, uptime, and RAM size were less likely to be flagged.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.