OpenSUpdater – Suspicious SFX Installer Execution

This rule detects the execution of a file named 'setup.exe' that is spawned by common interpreters (explorer.exe, msiexec.exe, powershell.exe, cmd.exe) where the command line arguments reference archiving or compression utilities like 'foobar2000', '7z', or '7zip'. This is a common pattern for self-extracting (SFX) installers or malicious droppers attempting to execute payload components.