BIOC Informational

Adobe Acrobat Reader drops an executable file to disk

The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt.

Module:
Platform Analytics
Agent event type:
File
Category:
Dropper
Status:
Enabled
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
Indicator:

File file name = *.exe , *.scr , *.dll , *.sys , *.com , *.bin , *.msi AND file path != *adobe\acrobat\*usercache.bin AND action type = create Process initiated by = acrord32.exe AND initiator signature = Signed AND initiator signer = *adobe systems* Host host os = windows

Preventable: yes