InstallUtil

T1218.004

Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org

About this technique

Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility. InstallUtil is a command-line utility that allows for installation and uninstallation of resources by executing specific installer components specified in .NET binaries. The InstallUtil binary may also be digitally signed by Microsoft and located in the .NET directories on a Windows system: C:\Windows\Microsoft.NET\Framework\v<version>\InstallUtil.exe and C:\Windows\Microsoft.NET\Framework64\v<version>\InstallUtil.exe.

InstallUtil may also be used to bypass application control through use of attributes within the binary that execute the class decorated with the attribute [System.ComponentModel.RunInstaller(true)].

Detection rules7

Rules on DetectionCode tagged with T1218.004.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk7

RuleTypeRiskData source
Windows DotNet Binary in Non Standard PathTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows InstallUtil Credential TheftTTPNULLSysmon EventID 7
Windows InstallUtil in Non Standard PathTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows InstallUtil Remote Network ConnectionAnomalyNULLSysmon EventID 1 AND Sysmon EventID 3, Cisco Network Visibility Module Flow Data
Windows InstallUtil Uninstall OptionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows InstallUtil Uninstall Option with NetworkTTPNULLSysmon EventID 1 AND Sysmon EventID 3
Windows InstallUtil URL in Command LineTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data

Groups2

Software4

Campaigns0

None recorded.

Procedure examples6

Groups2

Used byProcedure example
GroupmenuPass

menuPass has used InstallUtil.exe to execute malicious software.

GroupMustang Panda

Mustang Panda has used InstallUtil.exe to execute a malicious Beacon stager.

Software4

Used byProcedure example
MalwareChaes

Chaes has used Installutill to download content.

ToolCovenant

Covenant can create launchers via an InstallUtil XML file to install new Grunt listeners.

MalwareSaint Bot

Saint Bot had used `InstallUtil.exe` to download and deploy executables.

MalwareWhisperGate

WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender.

References2

  1. LOLBAS Installutil Open source
    LOLBAS. (n.d.). Installutil.exe. Retrieved July 31, 2019.
  2. MSDN InstallUtil Open source
    Microsoft. (n.d.). Installutil.exe (Installer Tool). Retrieved July 1, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.