Suspicious Download Via Certutil.EXE

 Original Source: [Sigma source]
Title: Suspicious Download Via Certutil.EXE
Status: test
Description:Detects the execution of certutil with certain flags that allow the utility to download files.
References:
  -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil
  -https://forensicitguy.github.io/agenttesla-vba-certutil-download/
  -https://news.sophos.com/en-us/2021/04/13/compromised-exchange-server-hosting-cryptojacker-targeting-other-exchange-servers/
  -https://twitter.com/egre55/status/1087685529016193025
  -https://lolbas-project.github.io/lolbas/Binaries/Certutil/
  -https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin
Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems)
Date: 2023-02-15
modified:2025-12-01
Tags:
  • -'attack.stealth'
  • -'attack.t1027'
  • -'attack.command-and-control'
  • -'attack.t1105'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\certutil.exe' OriginalFileName:'CertUtil.exe'   selection_flags:
    CommandLine|contains:
      -'urlcache '
      -'verifyctl '
      -'URL '

  selection_http:
    CommandLine|contains: 'http'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium