Obfuscated PowerShell MSI Install via WindowsInstaller COM

 Original Source: [Sigma source]
Title: Obfuscated PowerShell MSI Install via WindowsInstaller COM
Status: experimental
Description:Detects the execution of obfuscated PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`). The technique involves manipulating strings to hide functionality, such as constructing class names using string insertion (e.g., 'indowsInstaller.Installer'.Insert(0,'W')) and correcting malformed URLs (e.g., converting 'htps://' to 'https://') at runtime. This behavior is commonly associated with malware loaders or droppers that aim to bypass static detection by hiding intent in runtime-generated strings and using legitimate tools for code execution. The use of `InstallProduct` and COM object creation, particularly combined with hidden window execution and suppressed UI, indicates an attempt to install software (likely malicious) without user interaction.
References:
  -https://informationsecuritybuzz.com/the-real-danger-behind-a-simple-windows-shortcut/
  -https://redcanary.com/blog/threat-intelligence/intelligence-insights-may-2025/
  -https://www.virustotal.com/gui/file/f9710b0ba4de5fa0e7ec27da462d4d2fc6838eba83a19f23f6617a466bbad457
Author: Meroujan Antonyan (vx3r)
Date: 2025-05-27
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1027.010'
  • -'attack.t1218.007'
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell_ise.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell_ISE.EXE'
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_cli:
    CommandLine|contains|all:
      -'-ComObject'
      -'InstallProduct('
      -'.Insert('
      -'UILevel'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high