avatar

Pavan Pothamsetti

@pepete
Completionist
0 followers12 downloads8 copies2 likes41 views

2 detections

Detects installation of a Windows service (Security EventID 4697)
named after known VirtualBox Guest Additions components (VBoxGuest, VBoxMouse, VBoxSF,
VBoxService, VBoxVideo, VBoxWDDM). Fires when either:
(a) the service binary is registered outside the legitimate VirtualBox install/driver
paths, or
(b) a driver-class component name (VBoxGuest/VBoxMouse/VBoxSF/VBoxVideo/VBoxWDDM) is
registered as a user-mode/own-process service instead of a kernel or file-system
driver — a structural mismatch that cannot occur with the genuine component and is
a strong indicator of name-based masquerading (T1036.005).
Adversaries reuse trusted VirtualBox names to blend malicious persistence into expected
guest-VM/EDR-noise telemetry.
avatar
Pavan Pothamsetti@pepete
avatar
Detections.ai Community
2 months ago
4130
Detects installation of a Windows service (System EventID 7045)
named after known VirtualBox Guest Additions components (VBoxGuest, VBoxMouse, VBoxSF,
VBoxService, VBoxVideo, VBoxWDDM). Fires when either:
(a) the service binary is registered outside the legitimate VirtualBox install/driver
paths, or
(b) a driver-class component name (VBoxGuest/VBoxMouse/VBoxSF/VBoxVideo/VBoxWDDM) is
registered as a user-mode/own-process service instead of a kernel or file-system
driver — a structural mismatch that cannot occur with the genuine component and is
a strong indicator of name-based masquerading (T1036.005).
Adversaries reuse trusted VirtualBox names to blend malicious persistence into expected
guest-VM/EDR-noise telemetry.
avatar
Pavan Pothamsetti@pepete
avatar
Detections.ai Community
2 months ago
4111