Windows Process Creation: rundll32.exe InstallArcherSvc Execution

Flags rundll32.exe executions referencing InstallArcherSvc in the process command line on Windows.

FreeUnreviewedSigmahighv1
title: "Windows Process Creation: rundll32.exe InstallArcherSvc Execution"
id: 49ec03f7-b639-45a1-bd2a-032eb0ffdc75
status: test
description: This rule matches Windows process creation events where the command line contains both rundll32.exe and InstallArcherSvc, consistent with an Archer malware installer invocation. Attackers may use rundll32 to load or execute components via Windows-native tooling, blending malicious activity with legitimate system behavior. The detection relies on process creation telemetry and inspection of the full command line for the specified strings.
references:
  - https://www.virustotal.com/en/file/9b4971349ae85aa09c0a69852ed3e626c954954a3927b3d1b6646f139b930022/analysis/
  - https://www.hybrid-analysis.com/sample/9b4971349ae85aa09c0a69852ed3e626c954954a3927b3d1b6646f139b930022?environmentId=100
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2017/Malware/Fireball/proc_creation_win_malware_fireball.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-06-03
modified: 2021-11-27
tags:
  - attack.execution
  - attack.stealth
  - attack.t1218.011
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains|all:
      - rundll32.exe
      - InstallArcherSvc
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 3d4aebe0-6d29-45b2-a8a4-3dfde586a26d
    type: derived

What it detects

This rule matches Windows process creation events where the command line contains both rundll32.exe and InstallArcherSvc, consistent with an Archer malware installer invocation. Attackers may use rundll32 to load or execute components via Windows-native tooling, blending malicious activity with legitimate system behavior. The detection relies on process creation telemetry and inspection of the full command line for the specified strings.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.