MSI accessed a web page running a server-side script
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour
Required Data
XDR Agent
Detector Tags
LOLBIN Execution Analytics
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
System Binary Proxy Execution (T1218)
Severity
Informational
Description
The Microsoft installer command line included a URL to a web page running a server-side script, which is suspicious.
Attacker's Goals
An attacker may use this technique to install a malicious tool from a remote server.
Investigative actions
Check whether the URL is benign and if this was a desired behavior as part of its normal execution flow.
Variations
PreviousMshta.exe spawns from a browser process
NextMsiexec execution of an executable from an uncommon remote location
Was this helpful?
