Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. FRP

FRP

FRP, which stands for Fast Reverse Proxy, is an openly available tool that is capable of exposing a server located behind a firewall or Network Address Translation (NAT) to the Internet.FRP can support multiple protocols including TCP, UDP, and HTTP(S) and has been abused by threat actors to proxy command and control communications.[1][2][3][4]

ID: S1144
Type: TOOL
Platforms: Linux, macOS, Windows
Version: 1.0
Created: 10 July 2024
Last Modified: 30 July 2024
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

FRP has the ability to use HTTP and HTTPS to enable the forwarding of requests for internal services via domain name.[1]

EnterpriseT1059.007Command and Scripting Interpreter:JavaScript

FRP can support the use of a JSON configuration file.[1]

EnterpriseT1573.001Encrypted Channel:Symmetric Cryptography

FRP can use STCP (Secret TCP) with a preshared key to encrypt services exposed to public networks.[1]

.002Encrypted Channel:Asymmetric Cryptography

FRP can be configured to only accept TLS connections.[1]

EnterpriseT1046Network Service Discovery

As part of load balancingFRP can sethealthCheck.type = "tcp" orhealthCheck.type = "http" to check service status on specific hosts with TCPing or an HTTP request.[1]

EnterpriseT1095Non-Application Layer Protocol

FRP can communicate over TCP, TCP stream multiplexing, KERN Communications Protocol (KCP), QUIC, and UDP.[1]

EnterpriseT1572Protocol Tunneling

FRP can tunnel SSH and Unix Domain Socket communications over TCP between external nodes and exposed resources behind firewalls or NAT.[1]

EnterpriseT1090Proxy

FRP can proxy communications through a server in public IP space to local servers located behind a NAT or firewall.[1]

.003Multi-hop Proxy

TheFRP client can be configured to connect to the server through a proxy.[1]

EnterpriseT1049System Network Connections Discovery

FRP can use a dashboard and U/I to display the status of connections from the FRP client and server.[1]

Groups That Use This Software

Campaigns

IDNameDescription
C00573CX Supply Chain Attack

During the3CX Supply Chain Attack,AppleJeus used a compiled version of the publicly availableFRP software to move laterally within the 3CX network.AppleJeus dropped the software inC:\Windows\System32 namedMsMpEng.exe.[6]

C0043Indian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions included the use ofFRP to enable remote access.[7]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp