Windows Process Creation: Detect jpinst.exe/jpsetup.exe Installation Binary Indicators

Detects execution of jpinst.exe or jpsetup.exe on Windows, indicative of SNAKE installation activity.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-04
Updated
2026-07-31
title: "Windows Process Creation: Detect jpinst.exe/jpsetup.exe Installation Binary Indicators"
id: c4e4c389-6a41-4acb-8dc1-a99c1c6d92ad
status: test
description: This rule flags Windows process creation events where the executable name ends with jpinst.exe or jpsetup.exe, and excludes cases where the command line is empty or null. These binaries are highlighted as installation-time indicators associated with SNAKE malware in the referenced CISA report. The detection relies on process creation telemetry, specifically the process image path and the full command line.
references:
  - https://media.defense.gov/2023/May/09/2003218554/-1/-1/0/JOINT_CSA_HUNTING_RU_INTEL_SNAKE_MALWARE_20230509.PDF
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Malware/SNAKE/proc_creation_win_malware_snake_installer_exec.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-05-04
tags:
  - attack.execution
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith:
      - \jpsetup.exe
      - \jpinst.exe
  filter_main_cli_name:
    CommandLine:
      - jpinst.exe
      - jpinst
      - jpsetup.exe
      - jpsetup
  filter_main_cli_empty:
    CommandLine: ""
  filter_main_cli_null:
    CommandLine: null
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: d91ff53f-fd0c-419d-a6b8-ae038d5c3733
    type: derived