Malware
VaporRage
aka BOOMMIC
According to Mandiant, VaporRage or BOOMMIC, is a shellcode downloader written in C that communicates over HTTPS.
According to Mandiant, VaporRage or BOOMMIC, is a shellcode downloader written in C that communicates over HTTPS. Shellcode Payloads are retrieved from a hardcoded C2 that uses an encoded host_id generated from the targets domain and account name. BOOMMIC XOR decodes the downloaded shellcode payload in memory and executes it.
Family metadata imported from Malpedia (Fraunhofer FKIE).