Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols |
VaporRage can use HTTP to download shellcode from compromised websites.[1] |
Enterprise | T1140 | Deobfuscate/Decode Files or Information |
VaporRage can deobfuscate XOR-encoded shellcode prior to execution.[1] |
|
Enterprise | T1480 | Execution Guardrails |
VaporRage has the ability to check for the presence of a specific DLL and terminate if it is not found.[1] |
|
Enterprise | T1105 | Ingress Tool Transfer |
VaporRage has the ability to download malicious shellcode to compromised systems.[1] |
ID | Name | References |
---|---|---|
G0016 | APT29 |