ATT&CKReferencesGitHub Neo-reGeorg 2019

GitHub Neo-reGeorg 2019

L-Codes. (2019). Neo-reGeorg. Retrieved December 4, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1059.006
Python
MalwareNeo-reGeorg

Neo-reGeorg is a Python-based web shell.

T1071.001
Web Protocols
MalwareNeo-reGeorg

Neo-reGeorg can use customized HTTP headers.

T1090
Proxy
MalwareNeo-reGeorg

Neo-reGeorg has the ability to establish a SOCKS5 proxy on a compromised web server.

T1095
Non-Application Layer Protocol
MalwareNeo-reGeorg

Neo-reGeorg can create multiple TCP connections for a single session.

T1105
Ingress Tool Transfer
MalwarereGeorg

reGeorg has the ability to download files to targeted systems.

T1105
Ingress Tool Transfer
MalwareNeo-reGeorg

Neo-reGeorg has the ability to download files to targeted systems.

T1132.002
Non-Standard Encoding
MalwareNeo-reGeorg

Neo-reGeorg can use modified Base64 encoding to obfuscate communications.

T1505.003
Web Shell
MalwareNeo-reGeorg

Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections.

T1572
Protocol Tunneling
MalwareNeo-reGeorg

Neo-reGeorg can tunnel data in and out of targeted networks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.