Windows Process Creation: Detect IMEWDBLD.EXE Downloading Files via HTTP/HTTPS

Alerts when IMEWDBLD.exe runs with an HTTP/HTTPS URL, indicating arbitrary file downloads.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (SigmaHQ), DRL 1.1
Published
2023-11-09
Updated
2026-07-31
title: "Windows Process Creation: Detect IMEWDBLD.EXE Downloading Files via HTTP/HTTPS"
id: 8047dc53-0ff2-46b4-9d62-7991c82b9a24
related:
  - id: 8d7e392e-9b28-49e1-831d-5949c6281228
    type: derived
  - id: 863218bd-c7d0-4c52-80cd-0a96c09f54af
    type: derived
status: test
description: This rule identifies process executions of IMEWDBLD.exe where the command line contains an http:// or https:// URL, indicating an attempt to download an arbitrary file. Such behavior is relevant because attackers can use built-in binaries to fetch and stage payloads while blending into normal process activity. Telemetry required includes Windows process creation fields that provide the executable path/name and the full command line.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1105/T1105.md#atomic-test-10---windows---powershell-download
  - https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_imewbdld_download.yml
author: Swachchhanda Shrawan Poudel, Huntrule Team
date: 2023-11-09
tags:
  - attack.execution
  - attack.stealth
  - attack.t1218
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith: \IMEWDBLD.exe
    - OriginalFileName: imewdbld.exe
  selection_cli:
    CommandLine|contains:
      - http://
      - https://
  condition: all of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1