ATT&CKReferencesCyble Egregor Oct 2020

Cyble Egregor Oct 2020

Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareEgregor

Egregor's payloads are custom-packed, archived and encrypted to prevent analysis.

T1055
Process Injection
MalwareEgregor

Egregor can inject its payload into iexplore.exe process.

T1106
Native API
MalwareEgregor

Egregor has used the Windows API to make detection more difficult.

T1219
Remote Access Tools
MalwareEgregor

Egregor has checked for the LogMein event log in an attempt to encrypt files in remote machines.

T1497
Virtualization/Sandbox Evasion
MalwareEgregor

Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes.

T1574.001
DLL
MalwareEgregor

Egregor has used DLL side-loading to execute its payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.