Egregor Ransomware - An In-Depth Analysis
Tags
Common Information
Type | Value |
---|---|
UUID | c56edacc-68d6-403d-a62c-02773073c2b7 |
Fingerprint | a61351592d36b3d1 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Aug. 24, 2022, 7:24 a.m. |
Added to db | Sept. 26, 2022, 9:30 a.m. |
Last updated | Nov. 17, 2024, 6:54 p.m. |
Headline | Egregor Ransomware – An In-Depth Analysis |
Title | Egregor Ransomware - An In-Depth Analysis |
Detected Hints/Tags/Attributes | 48/2/59 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://blog.minerva-labs.com/egregor-ransomware-an-in-depth-analysis |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 622 | en.wikipedia.org |
|
Details | Domain | 2 | blog.minerva-labs.com |
|
Details | File | 11 | b.dll |
|
Details | File | 2 | %programdata%\dtb.dat |
|
Details | File | 9 | recover-files.txt |
|
Details | File | 46 | msftesql.exe |
|
Details | File | 57 | agntsvc.exe |
|
Details | File | 55 | tbirdconfig.exe |
|
Details | File | 199 | excel.exe |
|
Details | File | 58 | thebat.exe |
|
Details | File | 74 | procmon.exe |
|
Details | File | 64 | procexp.exe |
|
Details | File | 58 | sqlagent.exe |
|
Details | File | 54 | isqlplussvc.exe |
|
Details | File | 57 | mydesktopqos.exe |
|
Details | File | 52 | infopath.exe |
|
Details | File | 99 | steam.exe |
|
Details | File | 27 | procmon64.exe |
|
Details | File | 40 | procexp64.exe |
|
Details | File | 62 | sqlbrowser.exe |
|
Details | File | 56 | xfssvccon.exe |
|
Details | File | 57 | ocomm.exe |
|
Details | File | 91 | msaccess.exe |
|
Details | File | 35 | thebat64.exe |
|
Details | File | 6 | ipython.exe |
|
Details | File | 6 | wpython.exe |
|
Details | File | 66 | sqlwriter.exe |
|
Details | File | 119 | sqlservr.exe |
|
Details | File | 57 | mysqld.exe |
|
Details | File | 102 | mspub.exe |
|
Details | File | 63 | thunderbird.exe |
|
Details | File | 65 | python.exe |
|
Details | File | 30 | dumpcap.exe |
|
Details | File | 67 | oracle.exe |
|
Details | File | 58 | dbeng50.exe |
|
Details | File | 43 | mysqld-nt.exe |
|
Details | File | 74 | onenote.exe |
|
Details | File | 86 | visio.exe |
|
Details | File | 6 | qbw64.exe |
|
Details | File | 57 | synctime.exe |
|
Details | File | 57 | ocssd.exe |
|
Details | File | 57 | ocautoupds.exe |
|
Details | File | 40 | mysqld-opt.exe |
|
Details | File | 173 | outlook.exe |
|
Details | File | 323 | winword.exe |
|
Details | File | 41 | firefoxconfig.exe |
|
Details | File | 61 | dbsnmp.exe |
|
Details | File | 57 | encsvc.exe |
|
Details | File | 60 | mydesktopservice.exe |
|
Details | File | 92 | powerpnt.exe |
|
Details | File | 90 | wordpad.exe |
|
Details | File | 55 | sqbcoreservice.exe |
|
Details | File | 19 | qbw32.exe |
|
Details | sha256 | 1 | b9b71eb04d255b21e3272eef5f4c15d1c208183748dfad3569efd455d87879c6 |
|
Details | sha256 | 1 | 8d5ad342ea9fde48920a926780be432236d074d34f791b5c96ec3a418a1bbbd5 |
|
Details | Url | 1 | https://en.wikipedia.org/wiki/salsa20 |
|
Details | Url | 1 | https://en.wikipedia.org/wiki/rabbit_ |
|
Details | Url | 1 | https://www.blueliv.com/cyber-security-and-cyber-threat-intelligence-blog-blueliv/escape-from-the-maze |
|
Details | Url | 1 | https://blog.minerva-labs.com/minervalabs-vs-sekhmet |