IIS Components

T1505.004

Sub-technique of T1505 Server Software Component.View on attack.mitre.org

About this technique

Adversaries may install malicious components that run on Internet Information Services (IIS) web servers to establish persistence. IIS provides several mechanisms to extend the functionality of the web servers. For example, Internet Server Application Programming Interface (ISAPI) extensions and filters can be installed to examine and/or modify incoming and outgoing IIS web requests. Extensions and filters are deployed as DLL files that export three functions: Get{Extension/Filter}Version, Http{Extension/Filter}Proc, and (optionally) Terminate{Extension/Filter}. IIS modules may also be installed to extend IIS web servers.

Adversaries may install malicious ISAPI extensions and filters to observe and/or modify traffic, execute commands on compromised machines, or proxy command and control traffic. ISAPI extensions and filters may have access to all IIS web requests and responses. For example, an adversary may abuse these mechanisms to modify HTTP responses in order to distribute malicious commands/content to previously comprised hosts.

Adversaries may also install malicious IIS modules to observe and/or modify traffic. IIS 7.0 introduced modules that provide the same unrestricted access to HTTP requests and responses as ISAPI extensions and filters. IIS modules can be written as a DLL that exports RegisterModule, or as a .NET application that interfaces with ASP.NET APIs to access IIS HTTP requests.

Detection rules15

Rules on DetectionCode tagged with T1505.004.

Sigma5

Splunk10

RuleTypeRiskData source
Windows Disable Windows Event Logging Disable HTTP LoggingAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows IIS Components Add New ModuleAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows IIS Components Get-WebGlobalModule Module QueryHuntingNULLPowershell Installed IIS Modules
Windows IIS Components Module Failed to LoadAnomalyNULLWindows Event Log Application 2282
Windows IIS Components New Module AddedTTPNULLWindows IIS 29
Windows PowerShell Add Module to Global Assembly CacheTTPNULLPowershell Script Block Logging 4104
Windows PowerShell Disable HTTP LoggingTTPNULLPowershell Script Block Logging 4104
Windows PowerShell IIS Components WebGlobalModule UsageAnomalyNULLPowershell Script Block Logging 4104
Windows Server Software Component GACUtil Install to GACTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Shell or Script Execution From IIS DirectoryAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2

Groups0

None recorded.

Software3

Campaigns2

Procedure examples5

Software3

Used byProcedure example
MalwareIceApple

IceApple is an IIS post-exploitation framework, consisting of 18 modules that provide several functionalities.

MalwareOwaAuth

OwaAuth has been loaded onto Exchange servers and disguised as an ISAPI filter (owaauth.dll). The IIS w3wp.exe process then loads the malicious DLL.

MalwareRGDoor

RGDoor establishes persistence on webservers as an IIS module.

Campaigns2

Used byProcedure example
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors modified Internet Information Services (IIS) components to load suspicious .NET assemblies for persistence.

References9

  1. Dell TG-3390 Open source
    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.
  2. ESET IIS Malware 2021 Open source
    Hromcová, Z., Cherepanov, A. (2021). Anatomy of Native IIS Malware. Retrieved September 9, 2021.
  3. IIS Backdoor 2011 Open source
    Julien. (2011, February 2). IIS Backdoor. Retrieved June 3, 2021.
  4. MMPC ISAPI Filter 2012 Open source
    MMPC. (2012, October 3). Malware signed with the Adobe code signing certificate. Retrieved June 3, 2021.
  5. Microsoft IIS Modules Overview 2007 Open source
    Microsoft. (2007, November 24). IIS Modules Overview. Retrieved June 17, 2021.
  6. Microsoft ISAPI Extension All Incoming 2017 Open source
    Microsoft. (2017, June 16). Intercepting All Incoming IIS Requests. Retrieved June 3, 2021.
  7. Microsoft ISAPI Extension Overview 2017 Open source
    Microsoft. (2017, June 16). ISAPI Extension Overview. Retrieved June 3, 2021.
  8. Microsoft ISAPI Filter Overview 2017 Open source
    Microsoft. (2017, June 16). ISAPI Filter Overview. Retrieved June 3, 2021.
  9. Trustwave IIS Module 2013 Open source
    Grunzweig, J. (2013, December 9). The Curious Case of the Malicious IIS Module. Retrieved June 3, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.