Upatre, a malware downloader commonly spread through phishing emails, was observed using a simple anti-analysis technique to avoid detection in automated sandbox environments. The malware calls the Windows API GetTickCount and terminates if the infected system appears to have been running for less than roughly 12 minutes, a condition that often matches freshly booted virtual machines used for short-lived malware analysis.
The evasion tactic can cause Upatre samples to appear benign because they never execute their malicious payload during analysis. Researchers reported a surge in new Upatre samples using the method and noted that the downloader is frequently used to fetch the Dyre banking Trojan, which steals credentials. Palo Alto Networks said its WildFire platform mitigates the trick by modifying the GetTickCount return value so the malware believes the host has been running for hours.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks analyzed an Upatre sample discovered in March 2018 that used heavy obfuscation, process-hash-based virtual machine detection, in-memory loading, msiexec.exe injection, and persistence via a Run policy registry key. The variant also attempted to resolve the .bit domains bookreader[.]bit and doghunter[.]bit through hardcoded OpenNIC-associated DNS servers before sending encrypted HTTP POST traffic.
Palo Alto Networks said its WildFire analysis system defeats the technique by altering the GetTickCount return value so Upatre believes the machine has been running for hours and continues executing.
Brendan Griffin of Malcovery published a report covering the Upatre activity associated with the newly observed anti-analysis technique.
Palo Alto Networks reported recently detecting a surge of new Upatre samples using the uptime-check anti-analysis behavior, indicating the evasion method was being actively deployed in the wild.
The Upatre malware family added an anti-analysis technique that calls the Windows API GetTickCount and exits if system uptime is less than about 12 minutes, helping it evade short-lived sandbox analysis environments.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
researchcenter.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.