Potentially Suspicious Usage Of Qemu

 Original Source: [Sigma source]
Title: Potentially Suspicious Usage Of Qemu
Status: test
Description:Detects potentially suspicious execution of the Qemu utility in a Windows environment. Threat actors have leveraged this utility and this technique for achieving network access as reported by Kaspersky.
References:
  -https://securelist.com/network-tunneling-with-qemu/111803/
  -https://www.qemu.org/docs/master/system/invocation.html#hxtool-5
Author: Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR)
Date: 2024-06-03
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.t1090'
  • -'attack.t1572'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -'-m 1M'
      -'-m 2M'
      -'-m 3M'

    CommandLine|contains|all:
      -'restrict=off'
      -'-netdev '
      -'connect='
      -'-nographic'

  filter_main_normal_usecase:
    CommandLine|contains:
      -' -cdrom '
      -' type=virt '
      -' -blockdev '

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium