// soc investigation 2026-06-15
SOC317 Possible VM Detection Attempt
letsdefend Medium ✓ true positive
mitre/T1110-001mitre/T1078mitre/T1497-001mitre/T1033mitre/T1069-001mitre/T1082mitre/T1057
analyst verdict TRUE POSITIVE
✓

SOC317 — Possible VM Detection Attempt

Date: Aug 29, 2024 12:32 PM
Host: Anemon — 172[.]16[.]17[.]118
Severity: Medium | Category: Unauthorized Access
Verdict: ✅ True Positive | Scope: Single endpoint, contained


Timeline

TimeActivity
12:30:00RDP brute force success — user letsdefend — from 37[.]19[.]205[.]203
12:31:20whoami
12:31:26whoami /groups
12:31:47whoami /priv
12:32:03Full VM detection script — WMI Win32_ComputerSystem queried; pattern matched VirtualBox, VMware, KVM, Hyper-V, Xen
12:32:29net user
12:32:46net localgroup administrators
12:33:09systeminfo
12:33:33Get-WmiObject Win32_ComputerSystem (repeat)
12:34:41tasklist /svc

MITRE ATT&CK

Technique IDTacticTechnique
T1110.001Credential AccessBrute Force - Password Guessing
T1078Defense EvasionValid Accounts
T1497.001Defense EvasionVirtualization/Sandbox Evasion - System Checks
T1033DiscoverySystem Owner/User Discovery
T1069.001DiscoveryPermission Groups Discovery - Local Groups
T1082DiscoverySystem Information Discovery
T1057DiscoveryProcess Discovery

IOCs

TypeValue
Attacker IP37[.]19[.]205[.]203
Compromised Userletsdefend
Compromised HostAnemon
Host IP172[.]16[.]17[.]118
Processpowershell[.]exe
Parent Processpowershell[.]exe
WMI Class QueriedWin32_ComputerSystem

Analysis Reports

Nothing to link yet — add sandbox/VT links here once run.


Investigation Summary

Confirmed true positive. Attacker brute forced RDP from 37[.]19[.]205[.]203 and achieved successful login as user letsdefend at 12:30 PM, approximately two minutes before the alert fired. Post-access activity follows a structured recon pattern: the attacker first enumerated privileges via whoami variants, then executed a full VM detection script querying Win32_ComputerSystem for hypervisor strings (VMware, VirtualBox, KVM, Hyper-V, Xen), followed by user/group enumeration and broad system profiling via systeminfo and tasklist /svc. The repeat Get-WmiObject call at 12:33:33 aligns with the raw command that triggered the alert rule. Attack scope is confirmed to a single endpoint. Machine has been contained and credentials for letsdefend should be treated as compromised.


🔬 Analysis Reports 🦠 abuseip https://www.abuseipdb.com/check/37.19.205.203?page=5