Msiexec

T1218.007

Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org

About this technique

Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft.

Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs. Since it may be signed and native on Windows systems, msiexec.exe can be used to bypass application control solutions that do not account for its potential abuse. Msiexec.exe execution may also be elevated to SYSTEM privileges if the AlwaysInstallElevated policy is enabled.

Detection rules19

Rules on DetectionCode tagged with T1218.007.

Sigma9

RuleLevelLog source
Obfuscated PowerShell MSI Install via WindowsInstaller COMhighwindows / process_creation
DllUnregisterServer Function Call Via Msiexec.EXEmediumwindows / process_creation
MSI Installation From Webmediumwindows / NULL
Msiexec Quiet Installationmediumwindows / process_creation
MsiExec Web Installmediumwindows / process_creation
PowerShell WMI Win32_Product Install MSImediumwindows / ps_script
Suspicious MsiExec Embedding Parentmediumwindows / process_creation
Suspicious Msiexec Execute Arbitrary DLLmediumwindows / process_creation
Suspicious Msiexec Quiet Install From Remote Locationmediumwindows / process_creation

Splunk10

RuleTypeRiskData source
Uninstall App Using MsiExecTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows HTTP Network Communication From MSIExecAnomalyNULLSysmon EventID 1 AND Sysmon EventID 3, Cisco Network Visibility Module Flow Data
Windows MSI Rollback Script Deleted By Non-Msiexec ProcessTTPNULLSysmon EventID 23, Sysmon EventID 26
Windows MSIExec DLLRegisterServerTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows MsiExec HideWindow Rundll32 ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows MSIExec Remote DownloadAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data
Windows MSIExec Spawn Discovery CommandAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows MSIExec Spawn WinDBGTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows MSIExec Unregister DLLRegisterServerTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows MSIExec With Network ConnectionsTTPNULLSysmon EventID 1 AND Sysmon EventID 3

Groups6

Software23

Campaigns2

Procedure examples31

Groups6

Used byProcedure example
GroupAPT38

APT38 has used `msiexec.exe` to execute malicious files.

GroupMachete

Machete has used msiexec to install the Machete malware.

GroupMolerats

Molerats has used msiexec.exe to execute an MSI payload.

GroupRancor

Rancor has used msiexec to download and execute malicious installer files over HTTP.

GroupTA505

TA505 has used msiexec to download and execute malicious Windows Installer files.

GroupZIRCONIUM

ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files.

Software23

Used byProcedure example
MalwareAppleJeus

AppleJeus has been installed via MSI installer.

MalwareChaes

Chaes has used .MSI files as an initial way to start the infection chain.

MalwareClop

Clop can use msiexec.exe to disable security tools on the system.

MalwareDEADEYE

DEADEYE can use `msiexec.exe` for execution of malicious DLL.

MalwareDOWNIISSA

DOWNIISSA can create an instance of msiexec.exe and inject LODEINFO shellcode into the memory of the process.

MalwareDuqu

Duqu has used msiexec to execute malicious Windows Installer packages. Additionally, a PROPERTY=VALUE pair containing a 56-bit encryption key has been used to decrypt the main payload from the installer packages.

MalwareFlawedAmmyy

FlawedAmmyy has been installed via `msiexec.exe`.

MalwareGrandoreiro

Grandoreiro can use MSI files to execute DLLs.

View all 23 software examples

Campaigns2

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus delivered components using a Windows Installer package (.msi). The MSI installer extracted several files and executed the 3CXDesktopApp.exe, which loaded the malicious library file ffmpeg.dll.

CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda initial payloads downloaded a Windows Installer MSI file that in turn dropped follow-on files leading to installation of PlugX during RedDelta Modified PlugX Infection Chain Operations.

References4

  1. LOLBAS Msiexec Open source
    LOLBAS. (n.d.). Msiexec.exe. Retrieved April 18, 2019.
  2. Microsoft AlwaysInstallElevated 2018 Open source
    Microsoft. (2018, May 31). AlwaysInstallElevated. Retrieved December 14, 2020.
  3. Microsoft msiexec Open source
    Microsoft. (2017, October 15). msiexec. Retrieved January 24, 2020.
  4. TrendMicro Msiexec Feb 2018 Open source
    Co, M. and Sison, G. (2018, February 8). Attack Using Windows Installer msiexec.exe leads to LokiBot. Retrieved April 18, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.