• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    CRPx0 VM/Sandbox Discovery via WMI Before Payload Detonation

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 25 days ago•0•0•0

    Detects evidence of sandbox or virtualization evasion by identifying discovery commands that query WMI hypervisor classes or common virtual machine hardware strings. This activity is considered a precursor (pre-detonation check) when followed by the execution of encoded PowerShell commands or Python scripts on the same host, which is characteristic of the CRPx0 ClickFix attack chain.

    YARA-L

    Tags

    T1497 - Virtualization/Sandbox EvasionT1059.001 - PowerShellT1059.006 - PythonTA0005 - StealthTA0007 - DiscoveryTA0002 - ExecutionProcess CreationCommand ExecutionScript ExecutionPowershell Script ExecutionVirtual Machine ActivityWindowsWindows SysmonWindows Eventlog SecurityWindows Powershell Classic Logs

    Found in

    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026
    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026
    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026
    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?