Windows: Suspicious Cabinet (CAB) File Expansion via expand.exe from Uncommon Paths

Flags expand.exe ("-F:") extracting cabinets when used from suspicious/uncommon Windows paths.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Bhabesh Raj, X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-07-30
Updated
2026-07-31
title: "Windows: Suspicious Cabinet (CAB) File Expansion via expand.exe from Uncommon Paths"
id: 4c525ce6-793c-476a-84b0-fe3cd42cf064
status: test
description: This rule flags Windows executions of expand.exe with the -F argument that expand CAB files originating from potentially suspicious or uncommon directories (e.g., Perflogs, ProgramData, Public, Windows Temp, Admin$ shares, Temp under AppData). Attackers may use this behavior to extract embedded payloads or staging files while blending into normal-looking system activity. It relies on process creation telemetry capturing Image and CommandLine, including parent process context.
references:
  - https://labs.sentinelone.com/meteorexpress-mysterious-wiper-paralyzes-iranian-trains-with-epic-troll
  - https://blog.malwarebytes.com/threat-intelligence/2021/08/new-variant-of-konni-malware-used-in-campaign-targetting-russia/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml
author: Bhabesh Raj, X__Junior (Nextron Systems), Huntrule Team
date: 2021-07-30
modified: 2024-11-13
tags:
  - attack.stealth
  - attack.t1218
logsource:
  category: process_creation
  product: windows
detection:
  selection_cmd:
    Image|endswith: \expand.exe
    CommandLine|contains|windash: "-F:"
  selection_folders_1:
    CommandLine|contains:
      - :\Perflogs\
      - :\ProgramData
      - :\Users\Public\
      - :\Windows\Temp\
      - \Admin$\
      - \AppData\Local\Temp\
      - \AppData\Roaming\
      - \C$\
      - \Temporary Internet
  selection_folders_2:
    - CommandLine|contains|all:
        - :\Users\
        - \Favorites\
    - CommandLine|contains|all:
        - :\Users\
        - \Favourites\
    - CommandLine|contains|all:
        - :\Users\
        - \Contacts\
  filter_optional_dell:
    ParentImage: C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
    CommandLine|contains: C:\ProgramData\Dell\UpdateService\Temp\
  condition: selection_cmd and 1 of selection_folders_* and not 1 of filter_optional_*
falsepositives:
  - System administrator Usage
level: medium
license: DRL-1.1
related:
  - id: 9f107a84-532c-41af-b005-8d12a607639f
    type: derived