COOKIEBAG is an HTTP based backdoor which sends data to the C2 server as single-byte XOR and Base64 encoded strings in the HTTP Cookie header. The malware XOR's the data with 0x6B and Base64 encodes the result before sending it over the network in the HTTP header. ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.39