Malware.View on attack.mitre.org
Neo-reGeorg is an open-source web shell designed as a restructuring of reGeorg with improved usability, security, and fixes for exising reGeorg bugs.
| Technique | Procedure example |
|---|---|
| T1059.006 Python |
Neo-reGeorg is a Python-based web shell. |
| T1071.001 Web Protocols |
Neo-reGeorg can use customized HTTP headers. |
| T1090 Proxy |
Neo-reGeorg has the ability to establish a SOCKS5 proxy on a compromised web server. |
| T1095 Non-Application Layer Protocol |
Neo-reGeorg can create multiple TCP connections for a single session. |
| T1105 Ingress Tool Transfer |
Neo-reGeorg has the ability to download files to targeted systems. |
| T1132.002 Non-Standard Encoding |
Neo-reGeorg can use modified Base64 encoding to obfuscate communications. |
| T1505.003 Web Shell |
Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections. |
| T1572 Protocol Tunneling |
Neo-reGeorg can tunnel data in and out of targeted networks. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.