CompTIA CySA+ (CS0-003)Security OperationsMedium
A malware analyst detonates a sample in an automated sandbox but observes no malicious behavior in the report. Manual analysis of the binary reveals a call to GetTickCount followed by a conditional branch that terminates the process if execution time appears too short. Which sandbox evasion technique is being used?
- AAPI hammering to overwhelm the analysis engine
- BEnvironment fingerprinting via registry key checks
- CTiming-based evasion to detect accelerated or short-lived sandbox execution
- DProcess hollowing to hide the payload inside a legitimate process
Show answer & explanationAnswer & explanation
Correct answer: C. Timing-based evasion to detect accelerated or short-lived sandbox execution
Checking elapsed time (via GetTickCount) and terminating if execution appears too fast is a timing-based evasion technique; malware assumes sandboxes have limited analysis windows or accelerated clocks, so it stalls or exits to avoid revealing behavior.
Why the other options are wrong
- A. API hammering floods the sandbox with calls to exhaust resources, not measure elapsed time.
- B. Fingerprinting checks for VM artifacts like registry keys or driver names, not timing.
- D. Process hollowing replaces a legitimate process's memory with malicious code, unrelated to timing checks.
Timing-Based Sandbox Evasion
A technique where malware measures elapsed execution time (e.g., via GetTickCount or sleep calls) and withholds malicious behavior if the runtime appears too short, suspecting an automated sandbox.
- Sandboxes often have limited analysis windows (seconds to minutes)
- Malware may sleep or check timers to outlast automated analysis
- Extended/dynamic sandbox timeouts help counter this evasion
Memory trick: GetTickCount = malware peeking at its watch before deciding to 'perform.'