title: Potential Arbitrary File Download Via Cmdl32.EXE id: f37aba28-a9e6-4045-882c-d5004043b337 status: test description: | Detects execution of Cmdl32 with the "/vpn" and "/lan" flags. Attackers can abuse this utility in order to download arbitrary files via a configuration file. Inspect the location and the content of the file passed as an argument in order to determine if it is suspicious. references: - https://lolbas-project.github.io/lolbas/Binaries/Cmdl32/ - https://twitter.com/SwiftOnSecurity/status/1455897435063074824 - https://github.com/LOLBAS-Project/LOLBAS/pull/151 author: frack113 date: 2021-11-03 modified: 2024-04-22 tags: - attack.execution - attack.stealth - attack.t1218 - attack.t1202 logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: '\cmdl32.exe' - OriginalFileName: CMDL32.EXE selection_cli: CommandLine|contains|all: - '/vpn' - '/lan' condition: all of selection_* falsepositives: - Unknown level: medium