
Malware Sample Stalls to Dodge Sandboxes, Hides Behind Thin Infrastructure
A Windows binary posing as joduj.exe deliberately idles and polls the CPU clock to detect sandbox analysis before executing, a behavior confirmed by a malicious sandbox verdict and flagged by 55 of 75 engines. The engineering effort behind that evasion contrasts sharply with a thin, unverified network trail.
A Windows executable masquerading as joduj.exe (e9e732f7…) sits idle after launch, deliberately stalling for long stretches and polling the CPU clock directly to work out whether it has landed inside a sandbox before it will do anything else. That single behavioural signature — confirmed by a malicious verdict from the Yomi Hunter sandbox and flagged by 55 of 75 engines — is the strongest piece of evidence in this case, and it maps cleanly to time-based sandbox evasion [T1497.003].
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read