Can somebody explain how this will work? AFAIK it does not even check for obvious things such as vmware processes running in the background.
They could've achieved the same sandbox detection effect by just registering the domain and pointing it at 1.1.1.1 or whatever. The non-sandboxed connections would still fail, and no one else could take the domain.
That would leave a paper trail, potentially revealing who's behind the malware.