Ixeshe

S0015

Malware.View on attack.mitre.org

About this malware

Ixeshe is a malware family that has been used since at least 2009 against targets in East Asia.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

Ixeshe can collect data from a local system.

T1007
System Service Discovery

Ixeshe can list running services.

T1016
System Network Configuration Discovery

Ixeshe enumerates the IP address, network proxy settings, and domain name from a victim's system.

T1033
System Owner/User Discovery

Ixeshe collects the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location

Ixeshe has used registry values and file names associated with Adobe software, such as AcroRd32.exe.

T1057
Process Discovery

Ixeshe can list running processes.

T1059.003
Windows Command Shell

Ixeshe is capable of executing commands via cmd.

T1070.004
File Deletion

Ixeshe has a command to delete a file from the machine.

T1071.001
Web Protocols

Ixeshe uses HTTP for command and control.

T1082
System Information Discovery

Ixeshe collects the computer name of the victim's system during the initial infection.

T1083
File and Directory Discovery

Ixeshe can list file and directory information.

T1105
Ingress Tool Transfer

Ixeshe can download and execute additional files.

T1132.001
Standard Encoding

Ixeshe uses custom Base64 encoding schemes to obfuscate command and control traffic in the message body of HTTP requests.

T1547.001
Registry Run Keys / Startup Folder

Ixeshe can achieve persistence by adding itself to the HKCU\Software\Microsoft\Windows\CurrentVersion\Run Registry key.

T1564.001
Hidden Files and Directories

Ixeshe sets its own executable file's attributes to hidden.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Moran 2013 Open source
    Moran, N., & Villeneuve, N. (2013, August 12). Survival of the Fittest: New York Times Attackers Evolve Quickly [Blog]. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.