Windows Process Creation: 7z Archive with Specific Extensions via Wscript and Rundll32
Flags Windows process creation chaining 7z archive commands with .zip plus .txt/.log extensions and wscript+rundll32 context.
FreeUnreviewedSigmahighv1
windows-process-creation-7z-archive-with-specific-extensions-via-wscript-and-run-9be34ad0
title: "Windows Process Creation: 7z Archive with Specific Extensions via Wscript and Rundll32"
id: 0f65401e-2c20-4ec3-a698-53de0e89b68a
status: test
description: This rule identifies Windows process creation activity where command lines show 7z used to create password-protected archives containing specific file extensions (.zip with .txt or .log) and a related parent chain involving wscript.exe and rundll32.exe. It matters because such packaging and execution chaining can indicate staging behavior consistent with malicious payload preparation. The detection relies on process creation telemetry, including Image, CommandLine, ParentImage, and ParentCommandLine, to match these exact command-line patterns.
references:
- https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2020/TA/SolarWinds-Supply-Chain/proc_creation_win_apt_unc2452_cmds.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-01-22
modified: 2024-09-12
tags:
- attack.execution
- attack.t1059.001
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_generic_1:
CommandLine|contains:
- 7z.exe a -v500m -mx9 -r0 -p
- 7z.exe a -mx9 -r0 -p
CommandLine|contains|all:
- .zip
- .txt
selection_generic_2:
CommandLine|contains:
- 7z.exe a -v500m -mx9 -r0 -p
- 7z.exe a -mx9 -r0 -p
CommandLine|contains|all:
- .zip
- .log
selection_generic_3:
ParentCommandLine|contains|all:
- wscript.exe
- .vbs
CommandLine|contains|all:
- rundll32.exe
- C:\Windows
- .dll,Tk_
selection_generic_4:
ParentImage|endswith: \rundll32.exe
ParentCommandLine|contains|all:
- C:\Windows
- .dll
CommandLine|contains: "cmd.exe /C "
selection_generic_5:
ParentImage|endswith: \rundll32.exe
Image|endswith: \dllhost.exe
CommandLine: ""
condition: 1 of selection_generic_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 9be34ad0-b6a7-4fbd-91cf-fc7ec1047f5f
type: derived
What it detects
This rule identifies Windows process creation activity where command lines show 7z used to create password-protected archives containing specific file extensions (.zip with .txt or .log) and a related parent chain involving wscript.exe and rundll32.exe. It matters because such packaging and execution chaining can indicate staging behavior consistent with malicious payload preparation. The detection relies on process creation telemetry, including Image, CommandLine, ParentImage, and ParentCommandLine, to match these exact command-line patterns.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.