{"id":2501,"date":"2021-04-20T21:42:59","date_gmt":"2021-04-21T02:42:59","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2501"},"modified":"2021-04-20T21:43:01","modified_gmt":"2021-04-21T02:43:01","slug":"egregor-is-a-ransomware-that-has-been-very-active","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/","title":{"rendered":"Egregor is a ransomware that has been very active"},"content":{"rendered":"\n<p>It is known that the Egregor ransomware was detected for the first time in September 2020, in addition, it is estimated that based on the samples this malware has been located in Italy, France, Mexico, Germany, Japan, Saudi Arabia and the US This ransomware , believed to be a derivative of the Sekhmet ransomware; as, they have several similarities including API calls, functions, obfuscation techniques, and a similar ransom note. In addition, many of the Maze ransomware affiliates are presumed to be moving to become Egregor customers.<\/p>\n\n\n\n<p>This ransomware implements anti-analysis techniques, such as code obfuscation and payload encryption. In one of its execution stages the payload can only be decrypted if the correct key is provided on the command line of the process. Egregor can receive additional parameters through the command line. Also, to the encrypted files add a string or random characters as the new extension, for example, to a file called &#8220;image.jpg&#8221; change it to &#8220;image.jpg.JhWeA&#8221;.<\/p>\n\n\n\n<p>Egregor&#8217;s ransom note tells its victims that &#8220;soon the media, your partners and customers WILL KNOW about your PROBLEM &#8230; If you do not contact us in the next 3 DAYS, we will start publishing DATA.&#8221;<\/p>\n\n\n\n<p>Egregor has no way to spread, so it requires attackers to move laterally themselves, using Windows tools and other exploitation tools. In some cases, Cobalt Strike exploitation tools have been detected as part of Egregor&#8217;s attacks. The attackers used these tools to run scripts, gather information about other systems on the network, extract additional credentials, and spread the ransomware.<\/p>\n\n\n\n<p>To mitigate the possible impact of this ransomware, it is recommended to periodically back up information and keep backups with sensitive information without Internet access. It is also advisable to use a reliable security solution on each of the devices and keep it updated, avoid clicking on attachments that arrive in emails that we do not expect to receive, implement double authentication factor whenever possible, and connect to secure networks. avoiding mainly public Wi-Fi networks.<\/p>\n\n\n\n<p>Check also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/cyborg-ransomware-distributed-through-email\/\">Cyborg Ransomware distributed through Email<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/\">Vovalex \u2013 Ransomware posing as Windows utilities<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It is known that the Egregor ransomware was detected for the first time in September 2020, in addition, it is estimated that based on the samples this malware has been located in Italy, France, Mexico, Germany, Japan, Saudi Arabia and the US This ransomware , believed to be a derivative of the Sekhmet ransomware; as, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2502,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36,105],"class_list":["post-2501","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-ransomware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Egregor is a ransomware that has been very active - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"As we well know, ransomware has always been active and can be very harmful for companies and today we have to analyze one called Egregor....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Egregor is a ransomware that has been very active - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"As we well know, ransomware has always been active and can be very harmful for companies and today we have to analyze one called Egregor....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-04-21T02:42:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-04-21T02:43:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/new-ransom.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Egregor is a ransomware that has been very active\",\"datePublished\":\"2021-04-21T02:42:59+00:00\",\"dateModified\":\"2021-04-21T02:43:01+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/\"},\"wordCount\":352,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/new-ransom.jpg\",\"keywords\":[\"Cybersecurity\",\"Ransomware\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/\",\"name\":\"Egregor is a ransomware that has been very active - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/new-ransom.jpg\",\"datePublished\":\"2021-04-21T02:42:59+00:00\",\"dateModified\":\"2021-04-21T02:43:01+00:00\",\"description\":\"As we well know, ransomware has always been active and can be very harmful for companies and today we have to analyze one called Egregor....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/new-ransom.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/new-ransom.jpg\",\"width\":1200,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/egregor-is-a-ransomware-that-has-been-very-active\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Egregor is a ransomware that has been very active\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Egregor is a ransomware that has been very active - Truxgo Server Blog","description":"As we well know, ransomware has always been active and can be very harmful for companies and today we have to analyze one called Egregor....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/","og_locale":"es_MX","og_type":"article","og_title":"Egregor is a ransomware that has been very active - Truxgo Server Blog","og_description":"As we well know, ransomware has always been active and can be very harmful for companies and today we have to analyze one called Egregor....","og_url":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-04-21T02:42:59+00:00","article_modified_time":"2021-04-21T02:43:01+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/new-ransom.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Egregor is a ransomware that has been very active","datePublished":"2021-04-21T02:42:59+00:00","dateModified":"2021-04-21T02:43:01+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/"},"wordCount":352,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/new-ransom.jpg","keywords":["Cybersecurity","Ransomware"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/","url":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/","name":"Egregor is a ransomware that has been very active - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/new-ransom.jpg","datePublished":"2021-04-21T02:42:59+00:00","dateModified":"2021-04-21T02:43:01+00:00","description":"As we well know, ransomware has always been active and can be very harmful for companies and today we have to analyze one called Egregor....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/new-ransom.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/new-ransom.jpg","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Egregor is a ransomware that has been very active"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2501"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2501\/revisions"}],"predecessor-version":[{"id":2508,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2501\/revisions\/2508"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2502"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}