Bypassing Virtualization and Sandbox Technologies
ID: 75f9aba1-2b4c-5e9b-a796-7866fcbce3aa
STIX ID: report--75f9aba1-2b4c-5e9b-a796-7866fcbce3aa
Feed Name: TrustedSec blog
Threat Score
This report explains a sandbox-evasion technique that checks the number of CPU cores (commonly 1 in many sandbox/VM analysis environments) to decide whether to run malicious payloads; it cites Dyreza banking Trojan usage and notes the technique's inclusion in SET, arguing the method is simple, effective across languages (including PowerShell/Python), and reduces detection by common sandboxing products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
