Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org
Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft.
Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs. Since it may be signed and native on Windows systems, msiexec.exe can be used to bypass application control solutions that do not account for its potential abuse. Msiexec.exe execution may also be elevated to SYSTEM privileges if the AlwaysInstallElevated policy is enabled.
Rules on DetectionCode tagged with T1218.007.
| Rule | Level | Log source |
|---|---|---|
| Obfuscated PowerShell MSI Install via WindowsInstaller COM | high | windows / process_creation |
| DllUnregisterServer Function Call Via Msiexec.EXE | medium | windows / process_creation |
| MSI Installation From Web | medium | windows / NULL |
| Msiexec Quiet Installation | medium | windows / process_creation |
| MsiExec Web Install | medium | windows / process_creation |
| PowerShell WMI Win32_Product Install MSI | medium | windows / ps_script |
| Suspicious MsiExec Embedding Parent | medium | windows / process_creation |
| Suspicious Msiexec Execute Arbitrary DLL | medium | windows / process_creation |
| Suspicious Msiexec Quiet Install From Remote Location | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Uninstall App Using MsiExec | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows HTTP Network Communication From MSIExec | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 3, Cisco Network Visibility Module Flow Data |
| Windows MSI Rollback Script Deleted By Non-Msiexec Process | TTP | NULL | Sysmon EventID 23, Sysmon EventID 26 |
| Windows MSIExec DLLRegisterServer | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows MsiExec HideWindow Rundll32 Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows MSIExec Remote Download | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Windows MSIExec Spawn Discovery Command | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows MSIExec Spawn WinDBG | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows MSIExec Unregister DLLRegisterServer | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows MSIExec With Network Connections | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 3 |
| Used by | Procedure example |
|---|---|
| GroupAPT38 | APT38 has used `msiexec.exe` to execute malicious files. |
| GroupMachete | |
| GroupMolerats | Molerats has used msiexec.exe to execute an MSI payload. |
| GroupRancor | Rancor has used |
| GroupTA505 | TA505 has used |
| GroupZIRCONIUM | ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files. |
| Used by | Procedure example |
|---|---|
| MalwareAppleJeus | AppleJeus has been installed via MSI installer. |
| MalwareChaes | Chaes has used .MSI files as an initial way to start the infection chain. |
| MalwareClop | Clop can use msiexec.exe to disable security tools on the system. |
| MalwareDEADEYE | DEADEYE can use `msiexec.exe` for execution of malicious DLL. |
| MalwareDOWNIISSA | DOWNIISSA can create an instance of msiexec.exe and inject LODEINFO shellcode into the memory of the process. |
| MalwareDuqu | Duqu has used |
| MalwareFlawedAmmyy | FlawedAmmyy has been installed via `msiexec.exe`. |
| MalwareGrandoreiro | Grandoreiro can use MSI files to execute DLLs. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus delivered components using a Windows Installer package (.msi). The MSI installer extracted several files and executed the 3CXDesktopApp.exe, which loaded the malicious library file ffmpeg.dll. |
| CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda initial payloads downloaded a Windows Installer MSI file that in turn dropped follow-on files leading to installation of PlugX during RedDelta Modified PlugX Infection Chain Operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.