ATT&CKReferencesJoeSecurity Egregor 2020

JoeSecurity Egregor 2020

Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareEgregor

Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe.

T1082
System Information Discovery
MalwareEgregor

Egregor can perform a language check of the infected system and can query the CPU information (cupid).

T1124
System Time Discovery
MalwareEgregor

Egregor contains functionality to query the local/system time.

T1218.010
Regsvr32
MalwareEgregor

Egregor has used regsvr32.exe to execute malicious DLLs.

T1497.003
Time Based Checks
MalwareEgregor

Egregor can perform a long sleep (greater than or equal to 3 minutes) to evade detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.