Egregor Ransomware - An In-Depth Analysis
Common Information
Type Value
UUID c56edacc-68d6-403d-a62c-02773073c2b7
Fingerprint a61351592d36b3d1
Analysis status DONE
Considered CTI value 0
Text language
Published Aug. 24, 2022, 7:24 a.m.
Added to db Sept. 26, 2022, 9:30 a.m.
Last updated Nov. 17, 2024, 6:54 p.m.
Headline Egregor Ransomware – An In-Depth Analysis
Title Egregor Ransomware - An In-Depth Analysis
Detected Hints/Tags/Attributes 48/2/59
Attributes
Details Type #Events CTI Value
Details Domain 622
en.wikipedia.org
Details Domain 2
blog.minerva-labs.com
Details File 11
b.dll
Details File 2
%programdata%\dtb.dat
Details File 9
recover-files.txt
Details File 46
msftesql.exe
Details File 57
agntsvc.exe
Details File 55
tbirdconfig.exe
Details File 199
excel.exe
Details File 58
thebat.exe
Details File 74
procmon.exe
Details File 64
procexp.exe
Details File 58
sqlagent.exe
Details File 54
isqlplussvc.exe
Details File 57
mydesktopqos.exe
Details File 52
infopath.exe
Details File 99
steam.exe
Details File 27
procmon64.exe
Details File 40
procexp64.exe
Details File 62
sqlbrowser.exe
Details File 56
xfssvccon.exe
Details File 57
ocomm.exe
Details File 91
msaccess.exe
Details File 35
thebat64.exe
Details File 6
ipython.exe
Details File 6
wpython.exe
Details File 66
sqlwriter.exe
Details File 119
sqlservr.exe
Details File 57
mysqld.exe
Details File 102
mspub.exe
Details File 63
thunderbird.exe
Details File 65
python.exe
Details File 30
dumpcap.exe
Details File 67
oracle.exe
Details File 58
dbeng50.exe
Details File 43
mysqld-nt.exe
Details File 74
onenote.exe
Details File 86
visio.exe
Details File 6
qbw64.exe
Details File 57
synctime.exe
Details File 57
ocssd.exe
Details File 57
ocautoupds.exe
Details File 40
mysqld-opt.exe
Details File 173
outlook.exe
Details File 323
winword.exe
Details File 41
firefoxconfig.exe
Details File 61
dbsnmp.exe
Details File 57
encsvc.exe
Details File 60
mydesktopservice.exe
Details File 92
powerpnt.exe
Details File 90
wordpad.exe
Details File 55
sqbcoreservice.exe
Details File 19
qbw32.exe
Details sha256 1
b9b71eb04d255b21e3272eef5f4c15d1c208183748dfad3569efd455d87879c6
Details sha256 1
8d5ad342ea9fde48920a926780be432236d074d34f791b5c96ec3a418a1bbbd5
Details Url 1
https://en.wikipedia.org/wiki/salsa20
Details Url 1
https://en.wikipedia.org/wiki/rabbit_
Details Url 1
https://www.blueliv.com/cyber-security-and-cyber-threat-intelligence-blog-blueliv/escape-from-the-maze
Details Url 1
https://blog.minerva-labs.com/minervalabs-vs-sekhmet