Windows Process Creation: rundll32.exe InstallArcherSvc Execution
Flags rundll32.exe executions referencing InstallArcherSvc in the process command line on Windows.
FreeUnreviewedSigmahighv1
windows-process-creation-rundll32-exe-installarchersvc-execution-3d4aebe0
title: "Windows Process Creation: rundll32.exe InstallArcherSvc Execution"
id: 49ec03f7-b639-45a1-bd2a-032eb0ffdc75
status: test
description: This rule matches Windows process creation events where the command line contains both rundll32.exe and InstallArcherSvc, consistent with an Archer malware installer invocation. Attackers may use rundll32 to load or execute components via Windows-native tooling, blending malicious activity with legitimate system behavior. The detection relies on process creation telemetry and inspection of the full command line for the specified strings.
references:
- https://www.virustotal.com/en/file/9b4971349ae85aa09c0a69852ed3e626c954954a3927b3d1b6646f139b930022/analysis/
- https://www.hybrid-analysis.com/sample/9b4971349ae85aa09c0a69852ed3e626c954954a3927b3d1b6646f139b930022?environmentId=100
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2017/Malware/Fireball/proc_creation_win_malware_fireball.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-06-03
modified: 2021-11-27
tags:
- attack.execution
- attack.stealth
- attack.t1218.011
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains|all:
- rundll32.exe
- InstallArcherSvc
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 3d4aebe0-6d29-45b2-a8a4-3dfde586a26d
type: derived
What it detects
This rule matches Windows process creation events where the command line contains both rundll32.exe and InstallArcherSvc, consistent with an Archer malware installer invocation. Attackers may use rundll32 to load or execute components via Windows-native tooling, blending malicious activity with legitimate system behavior. The detection relies on process creation telemetry and inspection of the full command line for the specified strings.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.