Proxy Web Requests for Flash Player Installer from Unofficial Locations

Flags proxy downloads for Flash Player installer paths when the request host is not ending in .adobe.com.

FreeReviewedSigma · High · v2
Category
proxy
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-10-25
Updated
2026-07-31

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags proxy HTTP requests whose URI indicates downloading or installing Flash Player components, specifically matching paths like /flash_install.php and an .exe installer ending /install_flash_player.exe. Attackers may use unofficial or masquerading locations to deliver malicious installers under the guise of a legitimate update. It relies on proxy telemetry, including the requested URI and the client-facing host (cs-host), to identify traffic not ending in .adobe.com.

Related detections9 linkedT1204.002 — drag to rearrange
Suspicious macOS Installer Invocation Spawned via Zoom Opener Helper (via process_creation)
Suspicious OneNote Spawning Script Interpreter (via process_creation)
Scheduled Task Masquerading as Microsoft Wininet Config
Suspicious vbc.exe Spawned by Installer Process
Suspicious ALPHA SPIDER Rclone Exfiltration Tool Masquerading as System Binary (via process_creation)
Suspicious n8n Campaign RMM Installer Masquerading as OneDrive Document
Suspicious Axios NPM macOS Persistence Masquerading as Apple Service
Suspicious NFe-Themed Brazilian Lure Executable Execution
Malicious Spoolsv Process Masquerading From Non-System Path (via process_creation)
Proxy Web Requests for Flash Player Installer from Unofficial Locations
Pivot detection · T1204.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.