Potential File Download Via MS-AppInstaller Protocol Handler

 Original Source: [Sigma source]
Title: Potential File Download Via MS-AppInstaller Protocol Handler
Status: test
Description:Detects usage of the "ms-appinstaller" protocol handler via command line to potentially download arbitrary files via AppInstaller.EXE The downloaded files are temporarly stored in ":\Users\%username%\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\<RANDOM-8-CHAR-DIRECTORY>"
References:
  -https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/
Author: Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel
Date: 2023-11-09
modified:None
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'ms-appinstaller://?source='
      -'http'

  condition:selection
Falsepositives:
  -Unknown
Level: medium