Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareIxeshe | Ixeshe can collect data from a local system. |
| T1007 System Service Discovery |
MalwareIxeshe | Ixeshe can list running services. |
| T1016 System Network Configuration Discovery |
MalwareIxeshe | Ixeshe enumerates the IP address, network proxy settings, and domain name from a victim's system. |
| T1033 System Owner/User Discovery |
MalwareIxeshe | Ixeshe collects the username from the victim’s machine. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIxeshe | Ixeshe has used registry values and file names associated with Adobe software, such as AcroRd32.exe. |
| T1057 Process Discovery |
MalwareIxeshe | Ixeshe can list running processes. |
| T1059.003 Windows Command Shell |
MalwareIxeshe | |
| T1070.004 File Deletion |
MalwareIxeshe | Ixeshe has a command to delete a file from the machine. |
| T1071.001 Web Protocols |
MalwareIxeshe | Ixeshe uses HTTP for command and control. |
| T1082 System Information Discovery |
MalwareIxeshe | Ixeshe collects the computer name of the victim's system during the initial infection. |
| T1083 File and Directory Discovery |
MalwareIxeshe | Ixeshe can list file and directory information. |
| T1105 Ingress Tool Transfer |
MalwareIxeshe | Ixeshe can download and execute additional files. |
| T1132.001 Standard Encoding |
MalwareIxeshe | Ixeshe uses custom Base64 encoding schemes to obfuscate command and control traffic in the message body of HTTP requests. |
| T1203 Exploitation for Client Execution |
GroupAPT12 | APT12 has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities (CVE-2009-3129, CVE-2012-0158) and vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611). |
| T1204.002 Malicious File |
GroupAPT12 | APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareIxeshe | Ixeshe can achieve persistence by adding itself to the |
| T1564.001 Hidden Files and Directories |
MalwareIxeshe | Ixeshe sets its own executable file's attributes to hidden. |
| T1566.001 Spearphishing Attachment |
GroupAPT12 | APT12 has sent emails with malicious Microsoft Office documents and PDFs attached. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.