L-Codes. (2019). Neo-reGeorg. Retrieved December 4, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.006 Python |
MalwareNeo-reGeorg | Neo-reGeorg is a Python-based web shell. |
| T1071.001 Web Protocols |
MalwareNeo-reGeorg | Neo-reGeorg can use customized HTTP headers. |
| T1090 Proxy |
MalwareNeo-reGeorg | Neo-reGeorg has the ability to establish a SOCKS5 proxy on a compromised web server. |
| T1095 Non-Application Layer Protocol |
MalwareNeo-reGeorg | Neo-reGeorg can create multiple TCP connections for a single session. |
| T1105 Ingress Tool Transfer |
MalwarereGeorg | reGeorg has the ability to download files to targeted systems. |
| T1105 Ingress Tool Transfer |
MalwareNeo-reGeorg | Neo-reGeorg has the ability to download files to targeted systems. |
| T1132.002 Non-Standard Encoding |
MalwareNeo-reGeorg | Neo-reGeorg can use modified Base64 encoding to obfuscate communications. |
| T1505.003 Web Shell |
MalwareNeo-reGeorg | Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections. |
| T1572 Protocol Tunneling |
MalwareNeo-reGeorg | Neo-reGeorg can tunnel data in and out of targeted networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.