logo

Detecting Malicious Use of LOLBins, Pt. II | Huntress

ID: 11943064-fc1f-59f2-8831-971e7036ae32

STIX ID: report--11943064-fc1f-59f2-8831-971e7036ae32

Feed Name: Huntress Blog

Date Published: 2024-10-17

Date Updated: 2026-04-28

...
...

The report examines how Windows “living off the land” binaries (LOLBins) like finger.exe, curl.exe, and certutil.exe are used and demonstrates that malicious activity is often detectable by comparing command-line usage against environment baselines. It highlights sparse legitimate use of finger.exe versus widespread curl.exe activity and showcases anomalous PowerShell-spawned curl/certutil executions, including an incident where certutil, launched via encoded PowerShell under sqlservr.exe (from FortiClient EMS), attempted to install a rogue ScreenConnect instance but was blocked. It recommends leveraging SIEM/EDR telemetry—particularly PowerShell Event ID 600 command lines—and focusing on command-line uniqueness to surface suspicious executions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.