reGeorg

S1187

Malware.View on attack.mitre.org

About this malware

reGeorg is an open-source web shell written in Python that can be used as a proxy to bypass firewall rules and tunnel data in and out of targeted networks.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1021.001
Remote Desktop Protocol

reGeorg can be used to tunnel RDP connections.

T1021.002
SMB/Windows Admin Shares

reGeorg has the ability to tunnel SMB sessions.

T1021.004
SSH

reGeorg can communicate using SSH through an HTTP tunnel.

T1059.006
Python

reGeorg is a Python-based web shell.

T1071.001
Web Protocols

reGeorg can use HTTP to tunnel connections in and out of targeted networks.

T1090
Proxy

reGeorg can establish an HTTP or SOCKS proxy to tunnel data in and out of a network.

T1095
Non-Application Layer Protocol

reGeorg can tunnel TCP sessions into targeted networks.

T1105
Ingress Tool Transfer

reGeorg has the ability to download files to targeted systems.

T1505.003
Web Shell

reGeorg is a web shell that has been installed on exposed web servers for access to victim environments.

T1572
Protocol Tunneling

reGeorg can tunnel TCP sessions including RDP, SSH, and SMB through HTTP.

Groups that use it3

Campaigns0

None recorded.

References2

  1. Fortinet reGeorg MAR 2019 Open source
    FortiGard Labs. (2019, March 12). ReGeorg.HTTP.Tunnel. Retrieved December 3, 2024.
  2. GitHub reGeorg 2016 Open source
    xl7dev. (2016). reGeorg-master. Retrieved December 3, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.