BIOC Informational

Ping executed with loopback address

This seemingly strange "wait" mechanism is often used by malware to stall command execution.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Virtualization/Sandbox Evasion (T1497)
Indicator:

Process action type = execution AND target process cmd = *127.0.0.1* , *localhost* AND target process name = ping.exe

Preventable: yes