Sub-technique of T1505 Server Software Component.View on attack.mitre.org
Adversaries may install malicious components that run on Internet Information Services (IIS) web servers to establish persistence. IIS provides several mechanisms to extend the functionality of the web servers. For example, Internet Server Application Programming Interface (ISAPI) extensions and filters can be installed to examine and/or modify incoming and outgoing IIS web requests. Extensions and filters are deployed as DLL files that export three functions: Get{Extension/Filter}Version, Http{Extension/Filter}Proc, and (optionally) Terminate{Extension/Filter}. IIS modules may also be installed to extend IIS web servers.
Adversaries may install malicious ISAPI extensions and filters to observe and/or modify traffic, execute commands on compromised machines, or proxy command and control traffic. ISAPI extensions and filters may have access to all IIS web requests and responses. For example, an adversary may abuse these mechanisms to modify HTTP responses in order to distribute malicious commands/content to previously comprised hosts.
Adversaries may also install malicious IIS modules to observe and/or modify traffic. IIS 7.0 introduced modules that provide the same unrestricted access to HTTP requests and responses as ISAPI extensions and filters. IIS modules can be written as a DLL that exports RegisterModule, or as a .NET application that interfaces with ASP.NET APIs to access IIS HTTP requests.
Rules on DetectionCode tagged with T1505.004.
| Rule | Level | Log source |
|---|---|---|
| HTTP Logging Disabled On IIS Server | high | windows / NULL |
| Suspicious IIS Module Registration | high | windows / process_creation |
| ETW Logging/Processing Option Disabled On IIS Server | medium | windows / NULL |
| New Module Module Added To IIS Server | medium | windows / NULL |
| Previously Installed IIS Module Was Removed | low | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Disable Windows Event Logging Disable HTTP Logging | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows IIS Components Add New Module | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows IIS Components Get-WebGlobalModule Module Query | Hunting | NULL | Powershell Installed IIS Modules |
| Windows IIS Components Module Failed to Load | Anomaly | NULL | Windows Event Log Application 2282 |
| Windows IIS Components New Module Added | TTP | NULL | Windows IIS 29 |
| Windows PowerShell Add Module to Global Assembly Cache | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell Disable HTTP Logging | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell IIS Components WebGlobalModule Usage | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows Server Software Component GACUtil Install to GAC | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Shell or Script Execution From IIS Directory | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareIceApple | IceApple is an IIS post-exploitation framework, consisting of 18 modules that provide several functionalities. |
| MalwareOwaAuth | OwaAuth has been loaded onto Exchange servers and disguised as an ISAPI filter (owaauth.dll). The IIS w3wp.exe process then loads the malicious DLL. |
| MalwareRGDoor | RGDoor establishes persistence on webservers as an IIS module. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components. |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors modified Internet Information Services (IIS) components to load suspicious .NET assemblies for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.