COOKIEBAG - Possible infection

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

COOKIEBAG is an HTTP based backdoor which sends data to the C2 server as single-byte XOR and Base64 encoded strings in the HTTP Cookie
header. The malware XOR's the data with 0x6B and Base64 encodes the result before sending it over the network in the HTTP header.
ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.39