Suspicious Staged Payload Execution from User Downloads or Pictures Folder

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-06-11
Updated
2026-08-28

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects execution of attacker-staged binaries with names such as FunnyApp.exe, RedSun.exe, or z.exe from user Downloads or Pictures folders. These payloads were staged during a Huntress-investigated intrusion following VPN access and used to advance the attack, including bring-your-own-vulnerable-driver activity. Execution of these specific filenames from staging directories indicates deployment of hands-on-keyboard tooling.

Related detections8 linkedT1211 — drag to rearrange
Suspicious Vulnerable Driver Load for BYOVD Abuse by DragonForce Ransomware (via driver_load)
Malicious Vulnerable Driver Deployment for EDR Termination via file_event
Possible PAN-OS Auth Bypass via Double-Encoded Path Traversal to ztp_gate (CVE-2025-0108)
Malicious Bring-Your-Own-Vulnerable-Driver Load By BlackByte
Windows Process Command Lines Writing Malicious Files to C:\Windows\Fonts
Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Windows Application Error: MsMpEng.exe Crash Involving mpengine.dll
Windows Error Reporting: MsMpEng.exe Crash with mpengine.dll
Suspicious Staged Payload Execution from User Downloads or Pictures Folder
Pivot detection · T1211 · 8 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.