Malware authors are implementing the capability to check if their malicious code is running in the Any.Run malware analysis service. The service allows analysts to determine the malware behavior by recording any associated activity on files, registries, and network connections. A new malware campaign first spotted by the malware researcher JAMESWT employed a technique to detect the execution in an Any. run VM. If it detects that the program is running on Any.run it will display the message Any.run Detected! and halt the execution. This will cause the malware to not be executed so that the sandbox cannot analyze it.”]
Source: https://securityaffairs.co/wordpress/105830/malware/any-run-sandbox-evasion.html

