CompTIA CySA+ (CS0-003)Security OperationsMedium

A malware analyst detonates a sample in an automated sandbox but observes no malicious behavior in the report. Manual analysis of the binary reveals a call to GetTickCount followed by a conditional branch that terminates the process if execution time appears too short. Which sandbox evasion technique is being used?

  1. AAPI hammering to overwhelm the analysis engine
  2. BEnvironment fingerprinting via registry key checks
  3. CTiming-based evasion to detect accelerated or short-lived sandbox execution
  4. DProcess hollowing to hide the payload inside a legitimate process
Show answer & explanation

Correct answer: C. Timing-based evasion to detect accelerated or short-lived sandbox execution

Checking elapsed time (via GetTickCount) and terminating if execution appears too fast is a timing-based evasion technique; malware assumes sandboxes have limited analysis windows or accelerated clocks, so it stalls or exits to avoid revealing behavior.

Why the other options are wrong

  • A. API hammering floods the sandbox with calls to exhaust resources, not measure elapsed time.
  • B. Fingerprinting checks for VM artifacts like registry keys or driver names, not timing.
  • D. Process hollowing replaces a legitimate process's memory with malicious code, unrelated to timing checks.

Timing-Based Sandbox Evasion

A technique where malware measures elapsed execution time (e.g., via GetTickCount or sleep calls) and withholds malicious behavior if the runtime appears too short, suspecting an automated sandbox.

  • Sandboxes often have limited analysis windows (seconds to minutes)
  • Malware may sleep or check timers to outlast automated analysis
  • Extended/dynamic sandbox timeouts help counter this evasion

Memory trick: GetTickCount = malware peeking at its watch before deciding to 'perform.'

More Security Operations questions