FORENSIA

ATT&CK · T1218.004 · sub-technique

InstallUtil

Tactics: stealth

About

Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility. InstallUtil is a command-line utility that allows for installation and uninstallation of resources by executing specific installer components specified in .NET binaries. The InstallUtil binary may also be digitally signed by Microsoft and located in the .NET directories on a Windows system: <code>C:\Windows\Microsoft.NET\Framework\v<version>\InstallUtil.exe</code> and <code>C:\Windows\Microsoft.NET\Framework64\v<version>\InstallUtil.exe</code>. InstallUtil may also be used to bypass application control through use of attributes within the binary that execute the class decorated with the attribute <code>[System.ComponentModel.RunInstaller(true)]</code>.

Used by actors

2 known groups

Software

4 malware/tools implement this

ChaesWhisperGateSaint BotCovenant

Corpus indicators tagged with this technique

158 indicators in the corpus carry T1218.004.

IndicatorTypeFamilySevSrc
5b95e1d05d913676e9ebbd897a403ddfa6476524651a038d08ecebde29159b9asha256dependency_confusion801
59a260716d05c20229c6a46fe0a2fb5b80fa30c9c73a850222d9d3454426a60asha256ransomware801
f1c3ebe78bd8c38559bf3cfcc9a9fa37d221e31780774a3787e26160a61f5348hash803
6ed15aec7504081c3e14a9f6064d7b754aa283e4adb1a59edf3beff65369bc55sha256dependency_confusion801
adbc18f15019ef2ba6890b7996445c14350d57ba772eb33182889bc14ac47085sha256ransomware801
607cb58b8a592885eef5cfbe35ddce962741b0775c575f58cb3a96ca0ee893a6sha256ransomware801
3cbd65ae3ff5039324b03a66947a1d1b808ea5ddb09da917ed8f1323c34e80f7sha256dependency_confusion801
7f53fade6f3942f710b230d52a574fc6066ea282e739e417ca039800dc1bb08esha256dependency_confusion801
4b7301f02b8312ae6de614981f325dbbabee32166630618fdff74615d9a487basha256ransomware801
8d08136a1964c72b6b450b11d9bf2b3d3d289c26dfadfc9f021114eac2cea1casha256dependency_confusion801
c356aff1a01c2b0da472e584c8e3c8f875b9a24280435d42836a77b19f5a8c18hash803
e3ec5926a167d6e3359f98cdfb7ac3b2cce97652843056505d02e6d2898573c6sha256ransomware801
c725815cbb07ab5be8903e74ef8aea46ef9c25e4a3bc626ae94bfc1ae21df6e3sha256ransomware801
b7d50d0406afcd2efd87bf3bf8c4211719ba9817dd2e0ad62af10c933e765e28sha256ransomware801
c61b1941cf756eb7551f7c661743802362728b785adc22e860d269713dfb01a6hash803
d5b7247c497788cf0031ceb06e3df77a45fef59f1e49633dc7159816d64759b5hash803
e91fb249aa97be5c7931e430781167edfe7ba804720b5f643e6ab70b7e6e74ddhash803
b12b5720404e3d8794d72af064939dd953b6a8e0sha1dependency_confusion781
c2679a152084f3ebdb39aacb6ec6a23c61a46ae6sha1dependency_confusion781
d27fc9abbeccb60906d22906ef9a73bd05da2b7asha1dependency_confusion781
d497271a32633ddb4f56d548a13fefdab864b6e2sha1dependency_confusion781
ce1349eb9d4b2025d1a0dde651a690c7a471c5b0sha1dependency_confusion781
8f4e8b680d3e8d3f5ac39bd72882f713md5dependency_confusion761
999a63730c9634481d1d76955a2e76a8md5dependency_confusion761
edff4f58722c93d7c09ed71899416396md5dependency_confusion761
695e794631ef130583368770e7b81e98md5dependency_confusion761
87603ea025623b19954e460add532048md5dependency_confusion761
83601c3d4ed28e8d2be1b99beb8ec18cmd5dependency_confusion761
73bead922109a61e5f9f85771a7812c5md5dependency_confusion761
9a9ccd8b0e5d05f4ee77667b024844dbmd5dependency_confusion761

Showing the top 30 by severity of 158.