GOGGLES - 'HKLM\SYSTEM\CurrentControlSet\Services\dlserver\ImagePath'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

GOGGLES will periodically request a pre-configured URL, which contains encoded commands to either sleep or download and execute another
URL. The GOGGLES downloader makes extensive use of data encoding and encapsulation to obscure network traffic. GOGGLES is designed to
request a URL that is stored encoded in its resource section and then extract and decode a second URL from the data returned from the
server.
ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.46