Other than the titular TTP, some interesting behaviors here like using Notepad and Paint to perform network discovery. When attackers have UI access to the machine, disambiguating their behavior gets much harder.
But also yeah, a reminder that QEMU does run on Windows.
We are using a custom Sigma rule, on top of the EDR, to monitor Active Directory traffic originating from different VM products: VMware, Virtualbox, etc…
This may be a good detection opportunity, besides hunting for the binaries in suspicious locations. It was useful in red team engagements.
Gotcha:
It only works when the virtual machine runs in NAT mode. You need a security control that makes bridge mode useless.