BIOC
Informational
✕
Adobe Acrobat Reader drops an executable file to disk
The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Dropper
- Status:
- Enabled
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
Indicator:
File file name = *.exe , *.scr , *.dll , *.sys , *.com , *.bin , *.msi AND file path != *adobe\acrobat\*usercache.bin AND action type = create Process initiated by = acrord32.exe AND initiator signature = Signed AND initiator signer = *adobe systems* Host host os = windows
Preventable: yes