logo

12271_Blackberry_ContellatingBooklet_FULL_ModifiedLinks.indd

ID: 72491f70-fcc6-45ce-b01c-9ecce663da8a

STIX ID: report--72491f70-fcc6-45ce-b01c-9ecce663da8a

Threat Score

80/100

Uploaded: 2026-08-11

Published Date: 2021-11-15

Last Modified Date: 2021-11-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Finding Beacons in the Dark is a practitioner-focused CTI study of Cobalt Strike: it documents automated collection (Shodan/Rapid7/Censys), staging emulation to retrieve Beacons, static and dynamic decoding of shellcode/PE stagers, config extraction (XOR decoding, YARA rules), and large-scale clustering of artifacts (SSL public keys, JARM, PROCINJ_STUB, rich headers, imphashes). The report presents statistics from ~48k Beacons/6k+ Team Servers, demonstrates operational detection and hunting techniques, provides detection artefacts and YARA rules, and shows OSINT correlation linking infrastructure to many known actors and ransomware campaigns (e.g., APT41, DarkSide, Conti, WizardSpider, TA575), with guidance for XDR, SOC, IR, forensics and ML-based detection efforts.