Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareEgregor | Egregor has used tools to gather information about users. |
| T1036.004 Masquerade Task or Service |
MalwareEgregor | Egregor has masqueraded the svchost.exe process to exfiltrate data. |
| T1059.001 PowerShell |
MalwareEgregor | Egregor has used an encoded PowerShell command by a service created by Cobalt Strike for lateral movement. |
| T1069.002 Domain Groups |
MalwareEgregor | Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind. |
| T1071.001 Web Protocols |
MalwareEgregor | Egregor has communicated with its C2 servers via HTTPS protocol. |
| T1105 Ingress Tool Transfer |
MalwareEgregor | Egregor has the ability to download files from its C2 server. |
| T1197 BITS Jobs |
MalwareEgregor | Egregor has used BITSadmin to download and execute malicious DLLs. |
| T1484.001 Group Policy Modification |
MalwareEgregor | Egregor can modify the GPO to evade detection. |
| T1685 Disable or Modify Tools |
MalwareEgregor | Egregor has disabled Windows Defender to evade protections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.