ATT&CKReferencesTrend Micro IXESHE 2012

Trend Micro IXESHE 2012

Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareIxeshe

Ixeshe can collect data from a local system.

T1007
System Service Discovery
MalwareIxeshe

Ixeshe can list running services.

T1016
System Network Configuration Discovery
MalwareIxeshe

Ixeshe enumerates the IP address, network proxy settings, and domain name from a victim's system.

T1033
System Owner/User Discovery
MalwareIxeshe

Ixeshe collects the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareIxeshe

Ixeshe has used registry values and file names associated with Adobe software, such as AcroRd32.exe.

T1057
Process Discovery
MalwareIxeshe

Ixeshe can list running processes.

T1059.003
Windows Command Shell
MalwareIxeshe

Ixeshe is capable of executing commands via cmd.

T1070.004
File Deletion
MalwareIxeshe

Ixeshe has a command to delete a file from the machine.

T1071.001
Web Protocols
MalwareIxeshe

Ixeshe uses HTTP for command and control.

T1082
System Information Discovery
MalwareIxeshe

Ixeshe collects the computer name of the victim's system during the initial infection.

T1083
File and Directory Discovery
MalwareIxeshe

Ixeshe can list file and directory information.

T1105
Ingress Tool Transfer
MalwareIxeshe

Ixeshe can download and execute additional files.

T1132.001
Standard Encoding
MalwareIxeshe

Ixeshe uses custom Base64 encoding schemes to obfuscate command and control traffic in the message body of HTTP requests.

T1203
Exploitation for Client Execution
GroupAPT12

APT12 has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities (CVE-2009-3129, CVE-2012-0158) and vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611).

T1204.002
Malicious File
GroupAPT12

APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing.

T1547.001
Registry Run Keys / Startup Folder
MalwareIxeshe

Ixeshe can achieve persistence by adding itself to the HKCU\Software\Microsoft\Windows\CurrentVersion\Run Registry key.

T1564.001
Hidden Files and Directories
MalwareIxeshe

Ixeshe sets its own executable file's attributes to hidden.

T1566.001
Spearphishing Attachment
GroupAPT12

APT12 has sent emails with malicious Microsoft Office documents and PDFs attached.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.