Date: Aug 29, 2024 12:32 PM
Host: Anemon — 172[.]16[.]17[.]118
Severity: Medium | Category: Unauthorized Access
Verdict: ✅ True Positive | Scope: Single endpoint, contained
| Time | Activity |
|---|---|
| 12:30:00 | RDP brute force success — user letsdefend — from 37[.]19[.]205[.]203 |
| 12:31:20 | whoami |
| 12:31:26 | whoami /groups |
| 12:31:47 | whoami /priv |
| 12:32:03 | Full VM detection script — WMI Win32_ComputerSystem queried; pattern matched VirtualBox, VMware, KVM, Hyper-V, Xen |
| 12:32:29 | net user |
| 12:32:46 | net localgroup administrators |
| 12:33:09 | systeminfo |
| 12:33:33 | Get-WmiObject Win32_ComputerSystem (repeat) |
| 12:34:41 | tasklist /svc |
| Technique ID | Tactic | Technique |
|---|---|---|
| T1110.001 | Credential Access | Brute Force - Password Guessing |
| T1078 | Defense Evasion | Valid Accounts |
| T1497.001 | Defense Evasion | Virtualization/Sandbox Evasion - System Checks |
| T1033 | Discovery | System Owner/User Discovery |
| T1069.001 | Discovery | Permission Groups Discovery - Local Groups |
| T1082 | Discovery | System Information Discovery |
| T1057 | Discovery | Process Discovery |
| Type | Value |
|---|---|
| Attacker IP | 37[.]19[.]205[.]203 |
| Compromised User | letsdefend |
| Compromised Host | Anemon |
| Host IP | 172[.]16[.]17[.]118 |
| Process | powershell[.]exe |
| Parent Process | powershell[.]exe |
| WMI Class Queried | Win32_ComputerSystem |
Nothing to link yet — add sandbox/VT links here once run.
Confirmed true positive. Attacker brute forced RDP from 37[.]19[.]205[.]203 and achieved successful login as user letsdefend at 12:30 PM, approximately two minutes before the alert fired. Post-access activity follows a structured recon pattern: the attacker first enumerated privileges via whoami variants, then executed a full VM detection script querying Win32_ComputerSystem for hypervisor strings (VMware, VirtualBox, KVM, Hyper-V, Xen), followed by user/group enumeration and broad system profiling via systeminfo and tasklist /svc. The repeat Get-WmiObject call at 12:33:33 aligns with the raw command that triggered the alert rule. Attack scope is confirmed to a single endpoint. Machine has been contained and credentials for letsdefend should be treated as compromised.
🔬 Analysis Reports 🦠 abuseip https://www.abuseipdb.com/check/37.19.205.203?page=5