GooseEgg

Description

(Microsoft) The GooseEgg binary—which has included but is not limited to the file names justice.exe and DefragmentSrv.exe—takes one of four commands, each with different run paths. While the binary appears to launch a trivial given command, in fact the binary does this in a unique and sophisticated manner, likely to help conceal the activity.

Names

Name
GooseEgg

Category

Exploits

Type

  • Loader

Information

Malpedia

Other Information

Uuid

62423a14-facc-4b4c-8510-735f445a7883

Last Card Change

2024-12-27