AppX Package Installation Attempts Via AppInstaller.EXE

 Original Source: [Sigma source]
Title: AppX Package Installation Attempts Via AppInstaller.EXE
Status: test
Description:Detects DNS queries made by "AppInstaller.EXE". The AppInstaller is the default handler for the "ms-appinstaller" URI. It attempts to load/install a package from the referenced URL
References:
  -https://twitter.com/notwhickey/status/1333900137232523264
  -https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/
Author: frack113
Date: 2021-11-24
modified:2023-11-09
Tags:
  • -'attack.command-and-control'
  • -'attack.t1105'
Logsource:
  • product: windows
  • category: dns_query
Detection:
  selection:
    Image|startswith: 'C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_'
    Image|endswith: '\AppInstaller.exe'
  condition:selection
Falsepositives:
  -Unknown
Level: medium