Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareEgregor | Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe. |
| T1105 Ingress Tool Transfer |
MalwareEgregor | Egregor has the ability to download files from its C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEgregor | Egregor has been decrypted before execution. |
| T1218.011 Rundll32 |
MalwareEgregor | Egregor has used rundll32 during execution. |
| T1484.001 Group Policy Modification |
MalwareEgregor | Egregor can modify the GPO to evade detection. |
| T1486 Data Encrypted for Impact |
MalwareEgregor | Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.