Title:Obfuscated PowerShell MSI Install via WindowsInstaller COM Status:experimental Description:Detects the execution of obfuscated PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`).
The technique involves manipulating strings to hide functionality, such as constructing class names using string insertion (e.g., 'indowsInstaller.Installer'.Insert(0,'W')) and correcting
malformed URLs (e.g., converting 'htps://' to 'https://') at runtime. This behavior is commonly associated with malware loaders or droppers that aim to bypass static detection
by hiding intent in runtime-generated strings and using legitimate tools for code execution. The use of `InstallProduct` and COM object creation, particularly combined with
hidden window execution and suppressed UI, indicates an attempt to install software (likely malicious) without user interaction.
References: -https://informationsecuritybuzz.com/the-real-danger-behind-a-simple-windows-shortcut/ -https://redcanary.com/blog/threat-intelligence/intelligence-insights-may-2025/ -https://www.virustotal.com/gui/file/f9710b0ba4de5fa0e7ec27da462d4d2fc6838eba83a19f23f6617a466bbad457 Author: Meroujan Antonyan (vx3r) Date: 2025-05-27 modified:None Tags: