216.73.216.6

Tracking Pyramid C2: Identifying Post-Exploitation Servers in Hunt

· Published 13/02/2025 09:03 · Modified 13/02/2025 10:12

Export JSON

Essential information

Published
13/02/2025 09:03
Modified
13/02/2025 10:12
Tags
2025-02-13 c2 detection http server more_eggs network signatures open-source post-exploitation pyramid python ransomhub
Related entities
1 intrusion sets (apt), 10 techniques (mitre), 4 malware, 1 others

Description

, an framework in , is being used by threat actors for malicious purposes. The tool features a lightweight HTTP/S server for encrypted payload delivery, blending with legitimate activity. This analysis examines 's server, outlines for , and highlights recently identified servers. The infrastructure exhibits distinctive HTTP response patterns, allowing for structured queries. Nine IP addresses across different ports were identified matching the criteria. Three of these IPs were previously associated with activities. The post emphasizes the importance of proactive strategies to counter evolving tactics by adversaries using offensive security tools.

External references