Abuse of ie4uinit.exe from Non-Standard Directories
Adversaries may abuse the legitimate ie4uinit.exe binary by executing it from unauthorized locations to facilitate command execution via maliciously crafted .inf files.
The binary ie4uinit.exe (HTML Application Initializer) is a legitimate Windows system component often used for administrative tasks. Threat actors abuse this binary as a Living-off-the-Land (LotL) technique to proxy execution of arbitrary commands. By placing a specially prepared ie4uinit.inf file in a directory and triggering ie4uinit.exe from that same location, an attacker can coerce the binary into executing commands defined within the INF file. This technique is used for bypass, evasion, and persistence. Monitoring for instances where ie4uinit.exe is executed from paths other than the standard System32 or SysWOW64 directories allows defenders to identify potential abuse of this LOLBin.
Attack Chain
- Attacker identifies a writeable directory on the target system (e.g., C:\Users\Public).
- Attacker creates a malicious ie4uinit.inf file containing commands for execution within the target directory.
- Attacker drops or moves a copy of ie4uinit.exe into the same directory as the malicious .inf file.
- Attacker executes ie4uinit.exe from the non-standard path using a command-line interface.
- The binary parses the local ie4uinit.inf file instead of the intended system configuration.
- The binary executes the malicious commands defined in the .inf file with the privileges of the invoking user.
- Persistence is established or secondary payloads are downloaded.
Impact
Successful abuse of this technique allows an attacker to bypass security controls that restrict execution based on known binary paths, execute arbitrary commands under the user context, and establish persistence, potentially leading to full system compromise.
Recommendation
Deploy the provided Sigma rule to monitor process creation events for ie4uinit.exe execution occurring outside of verified system directories. Investigate any instances triggered by this rule, specifically inspecting the current working directory and the existence of local .inf files.
Immediate actions
Deploy Sigma rule to hunt for historical abuse
Mitigations
Implement endpoint path restrictions or application control to block binary execution from user-writeable directories
T1218
Detection coverage 1
Detect Abuse of ie4uinit.exe from Non-Standard Directories
mediumDetects the execution of ie4uinit.exe from directories other than C:\Windows\System32 or C:\Windows\SysWOW64, which may indicate LotL abuse.
Detection queries are available on the platform. Get full rules →