Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
Egregor's payloads are custom-packed, archived and encrypted to prevent analysis. |
| T1033 System Owner/User Discovery |
Egregor has used tools to gather information about users. |
| T1036.004 Masquerade Task or Service |
Egregor has masqueraded the svchost.exe process to exfiltrate data. |
| T1039 Data from Network Shared Drive |
Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel. |
| T1049 System Network Connections Discovery |
Egregor can enumerate all connected drives. |
| T1055 Process Injection |
Egregor can inject its payload into iexplore.exe process. |
| T1059.001 PowerShell |
Egregor has used an encoded PowerShell command by a service created by Cobalt Strike for lateral movement. |
| T1059.003 Windows Command Shell |
Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe. |
| T1069.002 Domain Groups |
Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind. |
| T1071.001 Web Protocols |
Egregor has communicated with its C2 servers via HTTPS protocol. |
| T1082 System Information Discovery |
Egregor can perform a language check of the infected system and can query the CPU information (cupid). |
| T1105 Ingress Tool Transfer |
Egregor has the ability to download files from its C2 server. |
| T1106 Native API |
Egregor has used the Windows API to make detection more difficult. |
| T1124 System Time Discovery |
Egregor contains functionality to query the local/system time. |
| T1140 Deobfuscate/Decode Files or Information |
Egregor has been decrypted before execution. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.