Skip to content

Commit 0490e31

Browse files
skaynumswachchhanda000nasbench
authored
Merge PR SigmaHQ#5674 from @skaynum - Add HTML File Opened From Download Folder
new: HTML File Opened From Download Folder --------- Co-authored-by: Swachchhanda Shrawan Poudel <[email protected]> Co-authored-by: Nasreddine Bencherchali <[email protected]>
1 parent 0aa2989 commit 0490e31

File tree

1 file changed

+39
-0
lines changed

1 file changed

+39
-0
lines changed
Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
title: HTML File Opened From Download Folder
2+
id: 538c5851-8c03-4724-8ec4-623bc7aadaea
3+
status: experimental
4+
description: |
5+
Detects web browser process opening an HTML file from a user's Downloads folder.
6+
This behavior is could be associated with phishing attacks where threat actors send HTML attachments to users.
7+
When a user opens such an attachment, it can lead to the execution of malicious scripts or the download of malware.
8+
During investigation, analyze the HTML file for embedded scripts or links, check for any subsequent downloads or process executions, and investigate the source of the email or message containing the attachment.
9+
references:
10+
- https://app.any.run/tasks/ae3c4ded-fd6a-43ed-8215-ba0ba574ad33
11+
- https://app.any.run/tasks/8901e2d5-0c5a-48ba-a8e9-10b5ed7e06f4
12+
author: Joseph Kamau
13+
date: 2025-12-05
14+
tags:
15+
- attack.t1598.002
16+
- attack.t1566.001
17+
- attack.initial-access
18+
- attack.reconnaissance
19+
- detection.threat-hunting
20+
logsource:
21+
product: windows
22+
category: process_creation
23+
detection:
24+
selection:
25+
Image|endswith:
26+
- '\brave.exe'
27+
- '\chrome.exe'
28+
- '\firefox.exe'
29+
- '\msedge.exe'
30+
- '\opera.exe'
31+
- '\vivaldi.exe'
32+
CommandLine|contains|all:
33+
- ':\users\'
34+
- '\Downloads\'
35+
- '.htm'
36+
condition: selection
37+
falsepositives:
38+
- Opening any HTML file located in users directories via a browser process will trigger this.
39+
level: low

0 commit comments

Comments
 (0)