ATT&CKReferencesCybereason Egregor Nov 2020

Cybereason Egregor Nov 2020

Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareEgregor

Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe.

T1105
Ingress Tool Transfer
MalwareEgregor

Egregor has the ability to download files from its C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareEgregor

Egregor has been decrypted before execution.

T1218.011
Rundll32
MalwareEgregor

Egregor has used rundll32 during execution.

T1484.001
Group Policy Modification
MalwareEgregor

Egregor can modify the GPO to evade detection.

T1486
Data Encrypted for Impact
MalwareEgregor

Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.