Image File Execution Options Injection

T1546.012

Sub-technique of T1546 Event Triggered Execution.View on attack.mitre.org

About this technique

Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers. IFEOs enable a developer to attach a debugger to an application. When a process is created, a debugger present in an application’s IFEO will be prepended to the application’s name, effectively launching the new process under the debugger (e.g., C:\dbg\ntsd.exe -g notepad.exe).

IFEOs can be set directly via the Registry or in Global Flags via the GFlags tool. IFEOs are represented as Debugger values in the Registry under HKLM\SOFTWARE{\Wow6432Node}\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<executable> where &lt;executable&gt; is the binary on which the debugger is attached.

IFEOs can also enable an arbitrary monitor program to be launched when a specified program silently exits (i.e. is prematurely terminated by itself or a second, non kernel-mode process). Similar to debuggers, silent exit monitoring can be enabled through GFlags and/or by directly modifying IFEO and silent process exit Registry values in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\.

Similar to Accessibility Features, on Windows Vista and later as well as Windows Server 2008 and later, a Registry key may be modified that configures "cmd.exe," or another program that provides backdoor access, as a "debugger" for an accessibility program (ex: utilman.exe). After the Registry is modified, pressing the appropriate key combination at the login screen while at the keyboard or when connected with Remote Desktop Protocol will cause the "debugger" program to be executed with SYSTEM privileges.

Similar to Process Injection, these values may also be abused to obtain privilege escalation by causing a malicious executable to be loaded and run in the context of separate processes on the computer. Installing IFEO mechanisms may also provide Persistence via continuous triggered invocation.

Malware may also use IFEO to impair defenses by registering invalid debuggers that redirect and effectively disable various system and security applications.

Detection rules4

Rules on DetectionCode tagged with T1546.012.

Sigma2

RuleLevelLog source
Potential Persistence Via App Paths Default Propertyhighwindows / registry_set
Potential Persistence Via GlobalFlagshighwindows / registry_set

Splunk2

RuleTypeRiskData source
Registry Keys Used For Privilege EscalationTTPNULLSysmon EventID 13
Windows Event Triggered Image File Execution Options InjectionHuntingNULLWindows Event Log Application 3000

Groups0

None recorded.

Software2

Campaigns1

Procedure examples3

Software2

Used byProcedure example
MalwareSDBbot

SDBbot has the ability to use image file execution options for persistence if it detects it is running with admin privileges on a Windows version newer than Windows 7.

MalwareSUNBURST

SUNBURST created an Image File Execution Options (IFEO) Debugger registry value for the process dllhost.exe to trigger the installation of Cobalt Strike.

Campaigns1

Used byProcedure example
CampaignC0032

During the C0032 campaign, TEMP.Veles modified and added entries within HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options to maintain persistence.

References8

  1. Elastic Process Injection July 2017 Open source
    Hosseini, A. (2017, July 18). Ten Process Injection Techniques: A Technical Survey Of Common And Trending Process Injection Techniques. Retrieved December 7, 2017.
  2. FSecure Hupigon Open source
    FSecure. (n.d.). Backdoor - W32/Hupigon.EMV - Threat Description. Retrieved December 18, 2017.
  3. Microsoft Dev Blog IFEO Mar 2010 Open source
    Shanbhag, M. (2010, March 24). Image File Execution Options (IFEO). Retrieved December 18, 2017.
  4. Microsoft GFlags Mar 2017 Open source
    Microsoft. (2017, May 23). GFlags Overview. Retrieved December 18, 2017.
  5. Microsoft Silent Process Exit NOV 2017 Open source
    Marshall, D. & Griffin, S. (2017, November 28). Monitoring Silent Process Exit. Retrieved June 27, 2018.
  6. Oddvar Moe IFEO APR 2018 Open source
    Moe, O. (2018, April 10). Persistence using GlobalFlags in Image File Execution Options - Hidden from Autoruns.exe. Retrieved June 27, 2018.
  7. Symantec Ushedix June 2008 Open source
    Symantec. (2008, June 28). Trojan.Ushedix. Retrieved December 18, 2017.
  8. Tilbury 2014 Open source
    Tilbury, C. (2014, August 28). Registry Analysis with CrowdResponse. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.