Windows: Suspicious HTA Startup Folder Creation by FoxitPDFReader.exe

Alerts on FoxitPDFReader.exe creating .hta files in the Startup Programs folder, which can indicate persistence.

FreeReviewedSigma · High · v5
Product
windows
Category
file_event
Author
Gregory (SigmaHQ), DRL 1.1
Published
2023-10-11
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags file creation events where FoxitPDFReader.exe creates a .hta file within the current user's Startup folder path under the Start Menu. Creating script files in Startup locations can provide persistence by executing content on user logon. It relies on Windows file event telemetry capturing the creating process image and the target filename/path.

Related detections6 linkedT1505.001 — drag to rearrange
Malicious SQL Server Lateral Movement with CLR Activation (via application)
Malicious SQL Server Dedicated Admin Connection (DAC) Suspicious Activity (via application)
Malicious SQL Server Sqlcmd Utility Abuse for Privilege Escalation (via process_creation)
Malicious SQL Server Dedicated Admin Connection (DAC) Mode Activated - Native (via application)
Malicious Command Shell Spawned by SQL Server via xp_cmdshell
Database SQL keyword matching suspicious queries (DROP/TRUNCATE/DUMP/SELECT *)
Windows: Suspicious HTA Startup Folder Creation by FoxitPDFReader.exe
Pivot detection · T1505.001 · 6 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.