File In Suspicious Location Encoded To Base64 Via Certutil.EXE

 Original Source: [Sigma source]
Title: File In Suspicious Location Encoded To Base64 Via Certutil.EXE
Status: test
Description:Detects the execution of certutil with the "encode" flag to encode a file to base64 where the files are located in potentially suspicious locations
References:
  -https://www.virustotal.com/gui/file/35c22725a92d5cb1016b09421c0a6cdbfd860fd4778b3313669b057d4a131cb7/behavior
  -https://www.virustotal.com/gui/file/427616528b7dbc4a6057ac89eb174a3a90f7abcf3f34e5a359b7a910d82f7a72/behavior
  -https://www.virustotal.com/gui/file/34de4c8beded481a4084a1fd77855c3e977e8ac643e5c5842d0f15f7f9b9086f/behavior
  -https://www.virustotal.com/gui/file/4abe1395a09fda06d897a9c4eb247278c1b6cddda5d126ce5b3f4f499e3b8fa2/behavior
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-15
modified:2024-03-05
Tags:
  • -'attack.stealth'
  • -'attack.t1027'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\certutil.exe' OriginalFileName:'CertUtil.exe'   selection_cli:
    CommandLine|contains|windash: '-encode'
  selection_extension:
    CommandLine|contains:
      -'\AppData\Roaming\'
      -'\Desktop\'
      -'\Local\Temp\'
      -'\PerfLogs\'
      -'\Users\Public\'
      -'\Windows\Temp\'
      -'$Recycle.Bin'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high