logo

Analysing Fileless Malware: Cobalt Strike Beacon

ID: 07bcd6b1-b54b-563a-b4ee-934ce2090554

STIX ID: report--07bcd6b1-b54b-563a-b4ee-934ce2090554

Feed Name: On the Hunt

Threat Score
70/100

Date Published: 2020-07-22

Date Updated: 2026-04-19

Author: Paul Newton

...
...

This report analyzes a FedEx-themed, multi-stage phishing campaign where a JNLP attachment launched a JAR that downloaded an executable (fedex912.exe → gennt.exe), established persistence under %PROGRAMDATA%, and used PowerShell to decode/decrypt and inject Cobalt Strike shellcode into memory, creating a fileless Beacon that connects to remote C2 infrastructure; the write-up includes JAR decompilation, executable behavior, PowerShell decoding, shellcode emulation, and provides IOCs (SHA256 hashes, domains, run location, and registry key).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.