Warning! Audit Deprecated
Information
GOGGLES will periodically request a pre-configured URL, which contains encoded commands to either sleep or download and execute another
URL. The GOGGLES downloader makes extensive use of data encoding and encapsulation to obscure network traffic. GOGGLES is designed to
request a URL that is stored encoded in its resource section and then extract and decode a second URL from the data returned from the
server.
ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.46