The really fun part is when malware authors add detections for "fake sandbox" and then real sandbox authors get to add those indicators.
Always the same bullshit with you people here. Could never possibly someone built a sub-optimal system -- it HAD to be management fucking with our good intentions!