NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareEgregor | Egregor's payloads are custom-packed, archived and encrypted to prevent analysis. |
| T1039 Data from Network Shared Drive |
MalwareEgregor | Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel. |
| T1049 System Network Connections Discovery |
MalwareEgregor | Egregor can enumerate all connected drives. |
| T1082 System Information Discovery |
MalwareEgregor | Egregor can perform a language check of the infected system and can query the CPU information (cupid). |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEgregor | Egregor has been decrypted before execution. |
| T1486 Data Encrypted for Impact |
MalwareEgregor | Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note. |
| T1497 Virtualization/Sandbox Evasion |
MalwareEgregor | Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.