Remote PDF Opened via Explorer with HTTP URL

Rule Info

Name
Remote PDF Opened via Explorer with HTTP URL
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects explorer.exe being invoked with an HTTP URL pointing to a remote PDF file. Attackers use this technique to display a decoy document while a malicious payload executes in the background, distracting the victim after LNK-based initial access. explorer.exe is not normally launched from the command line with a remote HTTP path; its appearance in such a context is a strong indicator of a scripted attack chain.
Date
2026-08-31 00:00:00
Modified
None
Id
3e4f5a6b-7c8d-9e0f-1a2b-3c4d5e6f7a8b
Tags
attack.initial-access attack.t1566.002 attack.execution attack.t1204.002 attack.stealth attack.t1036
Type
Nextron Sigma feed only (private)

Rule History