Windows Process Creation: 7z Archive with Specific Extensions via Wscript and Rundll32

Flags Windows process creation chaining 7z archive commands with .zip plus .txt/.log extensions and wscript+rundll32 context.

FreeUnreviewedSigmahighv1
title: "Windows Process Creation: 7z Archive with Specific Extensions via Wscript and Rundll32"
id: 0f65401e-2c20-4ec3-a698-53de0e89b68a
status: test
description: This rule identifies Windows process creation activity where command lines show 7z used to create password-protected archives containing specific file extensions (.zip with .txt or .log) and a related parent chain involving wscript.exe and rundll32.exe. It matters because such packaging and execution chaining can indicate staging behavior consistent with malicious payload preparation. The detection relies on process creation telemetry, including Image, CommandLine, ParentImage, and ParentCommandLine, to match these exact command-line patterns.
references:
  - https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2020/TA/SolarWinds-Supply-Chain/proc_creation_win_apt_unc2452_cmds.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-01-22
modified: 2024-09-12
tags:
  - attack.execution
  - attack.t1059.001
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_generic_1:
    CommandLine|contains:
      - 7z.exe a -v500m -mx9 -r0 -p
      - 7z.exe a -mx9 -r0 -p
    CommandLine|contains|all:
      - .zip
      - .txt
  selection_generic_2:
    CommandLine|contains:
      - 7z.exe a -v500m -mx9 -r0 -p
      - 7z.exe a -mx9 -r0 -p
    CommandLine|contains|all:
      - .zip
      - .log
  selection_generic_3:
    ParentCommandLine|contains|all:
      - wscript.exe
      - .vbs
    CommandLine|contains|all:
      - rundll32.exe
      - C:\Windows
      - .dll,Tk_
  selection_generic_4:
    ParentImage|endswith: \rundll32.exe
    ParentCommandLine|contains|all:
      - C:\Windows
      - .dll
    CommandLine|contains: "cmd.exe /C "
  selection_generic_5:
    ParentImage|endswith: \rundll32.exe
    Image|endswith: \dllhost.exe
    CommandLine: ""
  condition: 1 of selection_generic_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 9be34ad0-b6a7-4fbd-91cf-fc7ec1047f5f
    type: derived

What it detects

This rule identifies Windows process creation activity where command lines show 7z used to create password-protected archives containing specific file extensions (.zip with .txt or .log) and a related parent chain involving wscript.exe and rundll32.exe. It matters because such packaging and execution chaining can indicate staging behavior consistent with malicious payload preparation. The detection relies on process creation telemetry, including Image, CommandLine, ParentImage, and ParentCommandLine, to match these exact command-line patterns.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.