Prinz Eugen Ransomware Extended Sleep Anti-Sandbox Evasion
Detects processes that execute and remain dormant for more than 120 seconds before performing a high volume of file operations (greater than 50) or initiating a high volume of network connections (greater than 20). This pattern is consistent with malware or beaconing implants attempting to evade detection during automated sandbox analysis.
Splunk (SPL)

