COOKIEBAG

COOKIEBAGCOOKIEBAG

Description

his family of malware is a backdoor capable of file upload and download as well as providing remote interactive shell access to the compromised machine. Communication with the Command & Control (C2) servers uses a combination of single-byte XOR and Base64 encoded data in the Cookie and Set-Cookie HTTP header fields. Communication with the C2 servers is over port 80. Some variants install a registry key as means of a persistence mechanism. The hardcoded strings cited include a string of a command in common with several other APT1 families.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
COMBOS
Software
TSCookieRAT
Software
COLDCAT
Software
FortuneCookie
Software
TSCookie
Software
WEBC2-BOLID
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.