Malware.View on attack.mitre.org
reGeorg is an open-source web shell written in Python that can be used as a proxy to bypass firewall rules and tunnel data in and out of targeted networks.
| Technique | Procedure example |
|---|---|
| T1021.001 Remote Desktop Protocol |
reGeorg can be used to tunnel RDP connections. |
| T1021.002 SMB/Windows Admin Shares |
reGeorg has the ability to tunnel SMB sessions. |
| T1021.004 SSH |
reGeorg can communicate using SSH through an HTTP tunnel. |
| T1059.006 Python |
reGeorg is a Python-based web shell. |
| T1071.001 Web Protocols |
reGeorg can use HTTP to tunnel connections in and out of targeted networks. |
| T1090 Proxy |
reGeorg can establish an HTTP or SOCKS proxy to tunnel data in and out of a network. |
| T1095 Non-Application Layer Protocol |
reGeorg can tunnel TCP sessions into targeted networks. |
| T1105 Ingress Tool Transfer |
reGeorg has the ability to download files to targeted systems. |
| T1505.003 Web Shell |
reGeorg is a web shell that has been installed on exposed web servers for access to victim environments. |
| T1572 Protocol Tunneling |
reGeorg can tunnel TCP sessions including RDP, SSH, and SMB through HTTP. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.