{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:18:54Z","timestamp":1783610334829,"version":"3.55.0"},"reference-count":42,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2020,11,20]],"date-time":"2020-11-20T00:00:00Z","timestamp":1605830400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Malware analysis is fundamental for defending against prevalent cyber security threats and requires a means to deploy and study behavioural software traits as more sophisticated malware is developed. Traditionally, virtual machines are used to provide an environment that is isolated from production systems so as to not cause any adverse impact on existing infrastructure. Malware developers are fully aware of this and so will often develop evasion techniques to avoid detection within sandbox environments. In this paper, we conduct an investigation of anti-evasion malware triggers for uncovering malware that may attempt to conceal itself when deployed in a traditional sandbox environment. To facilitate our investigation, we developed a tool called MORRIGU that couples together both automated and human-driven analysis for systematic testing of anti-evasion methods using dynamic sandbox reconfiguration techniques. This is further supported by visualisation methods for performing comparative analysis of system activity when malware is deployed under different sandbox configurations. Our study reveals a variety of anti-evasion traits that are shared amongst different malware families, such as sandbox \u201cwear-and-tear\u201d, and Reverse Turing Tests (RTT), as well as more sophisticated malware samples that require multiple anti-evasion checks to be deployed. We also perform a comparative study using Cuckoo sandbox to demonstrate the limitations of adopting only automated analysis tools, to justify the exploratory analysis provided by MORRIGU. By adopting a clearer systematic process for uncovering anti-evasion malware triggers, as supported by tools like MORRIGU, this study helps to further the research of evasive malware analysis so that we can better defend against such future attacks.<\/jats:p>","DOI":"10.3390\/jcp1010003","type":"journal-article","created":{"date-parts":[[2020,11,20]],"date-time":"2020-11-20T02:09:07Z","timestamp":1605838147000},"page":"19-39","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":28,"title":["Investigating Anti-Evasion Malware Triggers Using Automated Sandbox Reconfiguration Techniques"],"prefix":"10.3390","volume":"1","author":[{"given":"Alan","family":"Mills","sequence":"first","affiliation":[{"name":"Computer Science Research Centre, University of the West of England, Bristol BS16 1QY, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3460-5609","authenticated-orcid":false,"given":"Phil","family":"Legg","sequence":"additional","affiliation":[{"name":"Computer Science Research Centre, University of the West of England, Bristol BS16 1QY, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,11,20]]},"reference":[{"key":"ref_1","first-page":"6","article-title":"A Survey on Automated Dynamic Malware-Analysis Techniques and Tools","volume":"44","author":"Egele","year":"2008","journal-title":"ACM Comput. Surv."},{"key":"ref_2","first-page":"1","article-title":"Dynamic malware analysis in the modern era\u2014A state of the art survey","volume":"52","author":"Nissim","year":"2019","journal-title":"ACM Comput. Surv."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., and Kirda, E. (2007, January 10\u201314). Limits of static analysis for malware detection. Proceedings of the Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007), Miami Beach, FL, USA.","DOI":"10.1109\/ACSAC.2007.21"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Bulazel, A., and Yener, B. (2017, January 16\u201317). A Survey On Automated Dynamic Malware Analysis Evasion and Counter-Evasion: PC, Mobile, and Web. Proceedings of the 1st Reversing and Offensive-Oriented Trends Symposium, Vienna, Austria.","DOI":"10.1145\/3150376.3150378"},{"key":"ref_5","unstructured":"(2020, April 23). Cuckoo Sandbox. Available online: https:\/\/cuckoosandbox.org."},{"key":"ref_6","unstructured":"JOE Security (2020, April 23). Available online: https:\/\/www.joesecurity.org."},{"key":"ref_7","unstructured":"(2020, April 23). HookMe. Available online: https:\/\/code.google.com\/archive\/p\/hookme\/."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Firdausi, I., Lim, C., Erwin, A., and Anto, S.N. (2010, January 2\u20133). Analysis of machine learning techniques used in behavior-based malware detection. Proceedings of the 2010 Second International Conference on Advances in Computing, Control, and Telecommunication Technologies, Jakarta, Indonesia.","DOI":"10.1109\/ACT.2010.33"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Tian, R., Islam, R., Batten, L., and Versteeg, S. (2010, January 19\u201320). Differentiating malware from cleanware using behavioural analysis. Proceedings of the 5th International Conference on Malicious and Unwanted Software, Nancy, France.","DOI":"10.1109\/MALWARE.2010.5665796"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Hansen, S.S., Larsen, T.M.T., Stevanovic, M., and Pedersen, J.M. (2016, January 8\u201310). An approach for detection and family classification of malware based on behavioral analysis. Proceedings of the International Conference on Computing, Networking and Communications (ICNC), Workshop on Computing, Networking and Communications (CNC), Columbus, OH, USA.","DOI":"10.1109\/ICCNC.2016.7440587"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Tobiyama, S., Yamaguchi, Y., Shimada, H., Ikuse, T., and Yagiup, T. (2016, January 10\u201314). Malware Detection with Deep Neural Network using Process Behavior. Proceedings of the 2016 IEEE 40th Annual Computer Software and Applications Conference, Atlanta, GA, USA.","DOI":"10.1109\/COMPSAC.2016.151"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"102526","DOI":"10.1016\/j.jnca.2019.102526","article-title":"The rise of machine learning for detection and classification of malware: Research developments, trends and challenges","volume":"153","author":"Gibert","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Mills, A., Spyridopoulos, T., and Legg, P. (2019, January 3\u20134). Efficient and Interpretable Real-Time Malware Detection Using Random-Forest. Proceedings of the International Conference on Cyber Situational Awareness, Data Analytics And Assessment (Cyber SA), Oxford, UK.","DOI":"10.1109\/CyberSA.2019.8899533"},{"key":"ref_14","unstructured":"Chumachenko, K. (2020, April 23). Machine Learning Methods for Malware Detection and Classification. Available online: https:\/\/www.theseus.fi\/handle\/10024\/123412."},{"key":"ref_15","unstructured":"(2020, April 23). Python-Scriptable Reverse Engineering Sandbox. Available online: https:\/\/github.com\/Cisco-Talos\/pyrebox."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"578","DOI":"10.1016\/j.cose.2018.05.010","article-title":"Early-stage malware prediction using recurrent neural networks","volume":"77","author":"Rhode","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_17","unstructured":"Wagner, M., Fischer, F., Luh, R., Haberson, A., Rind, A., Keim, D.A., Aigner, W., Borgo, R., Ganovelli, F., and Viola, I. (2015, January 25\u201329). A survey of visualization systems for malware analysis. Proceedings of the EG conference on visualization (EuroVis)-STARs, Sardinia, Italy."},{"key":"ref_18","unstructured":"LastLine (2019, June 23). Labs Report at RSA: Evasive Malware\u2019s Gone Mainstream. Available online: https:\/\/www.lastline.com\/labsblog\/labs-report-at-rsa-evasive-malwares-gone-mainstream\/."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Afianian, A., Niksefat, S., Sadeghiyan, B., and Baptiste, D. (2018). Malware Dynamic Analysis Evasion Techniques: A Survey. arXiv.","DOI":"10.1145\/3365001"},{"key":"ref_20","unstructured":"Keragala, D. (2016). Detecting Malware and Sandbox Evasion Techniques, SANS Institute InfoSec Reading Room."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1007\/s11416-008-0096-y","article-title":"Measuring virtual machine detection in malware using DSD tracer","volume":"6","author":"Lau","year":"2010","journal-title":"J. Comput. Virol."},{"key":"ref_22","unstructured":"Liston, T., and Skoudis, E. (2020, April 23). On the Cutting Edge: Thwarting Virtual Machine Detection (2006). Available online: https:\/\/ci.nii.ac.jp\/naid\/10021375130\/."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Miramirkhani, N., Appini, M.P., Nikiforakis, N., and Polychronakis, M. (2017, January 22\u201326). Spotless sandboxes: Evading malware analysis systems using wear-and-tear artifacts. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.42"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"2245","DOI":"10.1002\/sec.931","article-title":"A dynamic malware analyzer against virtual machine aware malicious software","volume":"7","author":"Acarman","year":"2014","journal-title":"Secur. Commun. Netw."},{"key":"ref_25","first-page":"100","article-title":"Challenges of Malware Analysis: Obfuscation Techniques","volume":"7","author":"Singh","year":"2018","journal-title":"Int. J. Inf. Secur. Sci."},{"key":"ref_26","unstructured":"Wueest, C. (2020, April 23). Threats to Virtual Environments. Symantec Security Response. Version. 2014. Available online: https:\/\/vxug.fakedoma.in\/archive\/Symantec\/threats-to-virtual-environments-14-en.pdf."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Brumley, D., Hartwig, C., Liang, Z., Newsome, J., Song, D., and Yin, H. (2008). Automatically identifying trigger-based behavior in malware. Botnet Detection, Springer.","DOI":"10.1007\/978-0-387-68768-1_4"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Mehra, M., and Pandey, D. (2015, January 17\u201320). Event triggered malware: A new challenge to sandboxing. Proceedings of the Annual IEEE India Conference (INDICON), New Delhi, India.","DOI":"10.1109\/INDICON.2015.7443327"},{"key":"ref_29","unstructured":"Ehteshamifar, S., Barresi, A., Gross, T.R., and Pradel, M. (2019). Easy to Fool? Testing the Anti-evasion Capabilities of PDF Malware Scanners. arXiv."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"249","DOI":"10.1016\/j.jnca.2017.10.004","article-title":"Countering cyber threats for industrial applications: An automated approach for malware evasion detection and analysis","volume":"103","author":"Noor","year":"2018","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Veerappan, C.S., Keong, P.L.K., Tang, Z., and Tan, F. (2018, January 5\u20138). Taxonomy on malware evasion countermeasures techniques. Proceedings of the IEEE 4th World Forum on Internet of Things (WF-IoT), Singapore.","DOI":"10.1109\/WF-IoT.2018.8355202"},{"key":"ref_32","unstructured":"Royal, P. (2020, January 12). Entrapment: Tricking Malware with Transparent, Scalable Malware Analysis. Black Hat. Available online: http:\/\/media.blackhat.com\/bh-eu-12\/Royal\/bh-eu-12-Royal-Entrapment-WP.pdf."},{"key":"ref_33","unstructured":"Chen, P., Huygens, C., Desmet, L., and Joosen, W. (June, January 30). Advanced or not? A comparative study of the use of anti-debugging and anti-VM techniques in generic and targeted malware. Proceedings of the IFIP International Conference on ICT Systems Security and Privacy Protection, Ghent, Belgium."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Lindorfer, M., Kolbitsch, C., and Comparetti, P.M. (2011, January 20\u201321). Detecting environment-sensitive malware. Proceedings of the International Workshop on Recent Advances in Intrusion Detection, Menlo Park, CA, USA.","DOI":"10.1007\/978-3-642-23644-0_18"},{"key":"ref_35","unstructured":"(2020, March 29). VirusShare.com. Available online: https:\/\/virusshare.com\/."},{"key":"ref_36","unstructured":"(2020, May 08). CIS Centre for Internet Security. Available online: https:\/\/www.cisecurity.org\/."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Walker, A., Amjad, M.F., and Sengupta, S. (2019, January 7\u20139). Cuckoo\u2019s Malware Threat Scoring and Classification: Friend or Foe?. Proceedings of the IEEE 9th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, USA.","DOI":"10.1109\/CCWC.2019.8666454"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"503","DOI":"10.1109\/JSYST.2015.2438442","article-title":"Automated Insider Threat Detection System Using User and Role-Based Profile Assessment","volume":"11","author":"Legg","year":"2017","journal-title":"IEEE Syst. J."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Legg, P.A. (2015, January 26). Visualizing the insider threat: Challenges and tools for identifying malicious user activity. Proceedings of the IEEE Symposium on Visualization for Cyber Security (VizSec), Chicago, IL, USA.","DOI":"10.1109\/VIZSEC.2015.7312772"},{"key":"ref_40","unstructured":"Lopez, J., Zhou, J., and Soriano, M. (2018). Deriving a Cost-Effective Digital Twin of an ICS to Facilitate Security Evaluation. Computer Security, Springer."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MSP.2011.67","article-title":"Stuxnet: Dissecting a Cyberwarfare Weapon","volume":"9","author":"Langner","year":"2011","journal-title":"IEEE Secur. Priv."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"804","DOI":"10.1016\/j.procs.2015.02.149","article-title":"Integrated Static and Dynamic Analysis for Malware Detection","volume":"46","author":"Shijo","year":"2015","journal-title":"Procedia Comput. Sci."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/1\/1\/3\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T10:34:41Z","timestamp":1760178881000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/1\/1\/3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,11,20]]},"references-count":42,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2021,3]]}},"alternative-id":["jcp1010003"],"URL":"https:\/\/doi.org\/10.3390\/jcp1010003","relation":{"has-preprint":[{"id-type":"doi","id":"10.20944\/preprints202010.0305.v1","asserted-by":"object"},{"id-type":"doi","id":"10.20944\/preprints202010.0305.v2","asserted-by":"object"}]},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,11,20]]}}}