Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe

Flags Windows execution of Advanced Installer PSF AI_STUBS stubs where OriginalFileName equals popupwrapper.exe.

FreeReviewedSigma · Low · v1
Product
windows
Category
process_creation
Author
Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-11-03
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies process execution on Windows where the image path ends with Advanced Installer Package Support Framework AI_STUBS executables and the process OriginalFileName is popupwrapper.exe. Attackers can abuse MSIX packaging components to run privileged or embedded helper stubs, potentially evading application control or maintaining stealth. Telemetry required includes process creation logs with the executed image path and OriginalFileName metadata.

Related detections9 linkedT1204.002 — drag to rearrange
Suspicious Program Execution From a Mounted ISO or Disk Image (via process_creation)
Malicious more_eggs LOLBIN Scriptlet Execution via ie4uinit BaseSettings Abuse (via process_creation)
Suspicious FileFix TypedPaths Entry Containing PowerShell or URL
Suspicious VBA Runtime Loaded by Process from OneNote Exported Directory
Suspicious vbc.exe Spawned by Installer Process
Suspicious n8n Campaign RMM Installer Masquerading as OneDrive Document
Suspicious NFe-Themed Brazilian Lure Executable Execution
Suspicious Executable Dropped in Public Users Directory Named Ctrlpanel (via file_event)
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Pivot detection · T1204.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.