ATT&CKReferencesIntrinsec Egregor Nov 2020

Intrinsec Egregor Nov 2020

Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareEgregor

Egregor has used tools to gather information about users.

T1036.004
Masquerade Task or Service
MalwareEgregor

Egregor has masqueraded the svchost.exe process to exfiltrate data.

T1059.001
PowerShell
MalwareEgregor

Egregor has used an encoded PowerShell command by a service created by Cobalt Strike for lateral movement.

T1069.002
Domain Groups
MalwareEgregor

Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind.

T1071.001
Web Protocols
MalwareEgregor

Egregor has communicated with its C2 servers via HTTPS protocol.

T1105
Ingress Tool Transfer
MalwareEgregor

Egregor has the ability to download files from its C2 server.

T1197
BITS Jobs
MalwareEgregor

Egregor has used BITSadmin to download and execute malicious DLLs.

T1484.001
Group Policy Modification
MalwareEgregor

Egregor can modify the GPO to evade detection.

T1685
Disable or Modify Tools
MalwareEgregor

Egregor has disabled Windows Defender to evade protections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.