Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org
Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility. InstallUtil is a command-line utility that allows for installation and uninstallation of resources by executing specific installer components specified in .NET binaries. The InstallUtil binary may also be digitally signed by Microsoft and located in the .NET directories on a Windows system: C:\Windows\Microsoft.NET\Framework\v<version>\InstallUtil.exe and C:\Windows\Microsoft.NET\Framework64\v<version>\InstallUtil.exe.
InstallUtil may also be used to bypass application control through use of attributes within the binary that execute the class decorated with the attribute [System.ComponentModel.RunInstaller(true)].
Rules on DetectionCode tagged with T1218.004.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows DotNet Binary in Non Standard Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows InstallUtil Credential Theft | TTP | NULL | Sysmon EventID 7 |
| Windows InstallUtil in Non Standard Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows InstallUtil Remote Network Connection | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 3, Cisco Network Visibility Module Flow Data |
| Windows InstallUtil Uninstall Option | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows InstallUtil Uninstall Option with Network | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 3 |
| Windows InstallUtil URL in Command Line | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupmenuPass | menuPass has used |
| GroupMustang Panda | Mustang Panda has used |
| Used by | Procedure example |
|---|---|
| MalwareChaes | Chaes has used Installutill to download content. |
| ToolCovenant | Covenant can create launchers via an InstallUtil XML file to install new Grunt listeners. |
| MalwareSaint Bot | Saint Bot had used `InstallUtil.exe` to download and deploy executables. |
| MalwareWhisperGate | WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.