Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareEgregor | Egregor's payloads are custom-packed, archived and encrypted to prevent analysis. |
| T1055 Process Injection |
MalwareEgregor | Egregor can inject its payload into iexplore.exe process. |
| T1106 Native API |
MalwareEgregor | Egregor has used the Windows API to make detection more difficult. |
| T1219 Remote Access Tools |
MalwareEgregor | Egregor has checked for the LogMein event log in an attempt to encrypt files in remote machines. |
| T1497 Virtualization/Sandbox Evasion |
MalwareEgregor | Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes. |
| T1574.001 DLL |
MalwareEgregor | Egregor has used DLL side-loading to execute its payload. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.