ATT&CKReferencesNHS Digital Egregor Nov 2020

NHS Digital Egregor Nov 2020

NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareEgregor

Egregor's payloads are custom-packed, archived and encrypted to prevent analysis.

T1039
Data from Network Shared Drive
MalwareEgregor

Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel.

T1049
System Network Connections Discovery
MalwareEgregor

Egregor can enumerate all connected drives.

T1082
System Information Discovery
MalwareEgregor

Egregor can perform a language check of the infected system and can query the CPU information (cupid).

T1140
Deobfuscate/Decode Files or Information
MalwareEgregor

Egregor has been decrypted before execution.

T1486
Data Encrypted for Impact
MalwareEgregor

Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note.

T1497
Virtualization/Sandbox Evasion
MalwareEgregor

Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.