AML.T0097
MITRE ATLAS / Virtualization/Sandbox Evasion
Adversaries detect virtualization and analysis environments and change behavior to avoid them, staying dormant while under inspection and acting only on real targets.
In plain English
Malicious code checks whether it is being watched. In a sandbox it behaves; on a real machine it runs, which is why clean analysis results do not prove much on their own.