Rule Info
Name
Remote PDF Opened via Explorer with HTTP URL
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects explorer.exe being invoked with an HTTP URL pointing to a remote PDF file.
Attackers use this technique to display a decoy document while a malicious payload
executes in the background, distracting the victim after LNK-based initial access.
explorer.exe is not normally launched from the command line with a remote HTTP path;
its appearance in such a context is a strong indicator of a scripted attack chain.
Date
2026-08-31 00:00:00
Modified
None
Id
3e4f5a6b-7c8d-9e0f-1a2b-3c4d5e6f7a8b
Tags
attack.initial-access attack.t1566.002 attack.execution attack.t1204.002 attack.stealth attack.t1036
Type
Nextron Sigma feed only (private)
