Tracking Pyramid C2: Identifying Post-Exploitation Servers in Hunt
ID: 9171d20c-8f87-51ad-93eb-85a98a6a290b
STIX ID: report--9171d20c-8f87-51ad-93eb-85a98a6a290b
Feed Name: Hunt.io Blog
Threat Score
This report analyzes Pyramid, an open-source Python post-exploitation C2 server, describing distinctive HTTP/S behaviors (401 responses, BaseHTTP/Python Server header, WWW-Authenticate Basic realm, and a specific JSON error body hash), provides detection query examples to find related infrastructure, and lists identified IPs and domains—several of which overlap with ransomware-affiliated activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
