Suspicious Persistence Via VMwareToolBoxCmd.EXE VM State Change Script

 Original Source: [Sigma source]
Title: Suspicious Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
Status: test
Description:Detects execution of the "VMwareToolBoxCmd.exe" with the "script" and "set" flag to setup a specific script that's located in a potentially suspicious location to run for a specific VM state
References:
  -https://bohops.com/2021/10/08/analyzing-and-detecting-a-vmtools-persistence-technique/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-06-14
modified:None
Tags:
  • -'attack.execution'
  • -'attack.persistence'
  • -'attack.t1059'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_bin_img:
Image|endswith:'\VMwareToolBoxCmd.exe' OriginalFileName:'toolbox-cmd.exe'   selection_bin_cli:
    CommandLine|contains|all:
      -' script '
      -' set '

  selection_susp_paths:
    CommandLine|contains:
      -':\PerfLogs\'
      -':\Temp\'
      -':\Windows\System32\Tasks\'
      -':\Windows\Tasks\'
      -':\Windows\Temp\'
      -'\AppData\Local\Temp'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high