From 5806d33e7066cd1e73b32baee75d5fc5e1ee30ea Mon Sep 17 00:00:00 2001 From: Conor Richard Date: Mon, 26 Oct 2020 19:43:55 -0400 Subject: [PATCH] Update Certutil.yml --- yml/OSBinaries/Certutil.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/yml/OSBinaries/Certutil.yml b/yml/OSBinaries/Certutil.yml index 83afab2..c58c55d 100644 --- a/yml/OSBinaries/Certutil.yml +++ b/yml/OSBinaries/Certutil.yml @@ -56,7 +56,7 @@ Full_Path: - Path: C:\Windows\System32\certutil.exe - Path: C:\Windows\SysWOW64\certutil.exe Code_Sample: - - Code:546573745f62795f4c696f72(example of the encoded hexadecimal file) + - Code: Detection: - IOC: Certutil.exe creating new files on disk - IOC: Useragent Microsoft-CryptoAPI/10.0