BIOC
Informational
✕
Ping executed with loopback address
This seemingly strange "wait" mechanism is often used by malware to stall command execution.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Virtualization/Sandbox Evasion (T1497)
Indicator:
Process action type = execution AND target process cmd = *127.0.0.1* , *localhost* AND target process name = ping.exe
Preventable: yes