Suspicious URL Opening via CMD Start Command

Rule Info

Name
Suspicious URL Opening via CMD Start Command
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects usage of cmd.exe to start a URL, which opens a web browser and may trigger a file download if the content cannot be rendered. Threat Actors may use this cmd one-liner to download second-stage payloads for execution.
Reference
Internal Research
Date
2025-06-25 00:00:00
Modified
None
Id
4a27ee6b-f54b-4f90-a9ae-5f14e7d17d1c
Tags
attack.execution attack.t1059.003 attack.command-and-control attack.t1105
Type
Nextron Sigma feed only (private)

Rule History