s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932522 high

📛 Threat Title

Sliver: URL that delivers a malware payload http://myanmar001.xyz/implant.exe

Category: Sliver Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Sliver. Confidence: 95. First seen: 2026-09-25 00:41:52 UTC. Reporter: whack_sh. Tags: exe, sliver.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url http://myanmar001.xyz/implant.exe

IOC database

Type
url
Value
http://myanmar001.xyz/implant.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that delivers a malware payload attributed to Sliver

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Sliver. Confidence: 95. First seen: 2026-09-25 00:41:52 UTC. Reporter: whack_sh. Tags: exe, sliver.

Remediations (10)

  • web:any.run

    Sliver is a C2 framework that allows attackers to maintain access, control systems, and conduct further attacks while remaining undetected.

  • web:any.run

    Online sandbox report for implant.exe, tagged as sliver , golang, verdict: Malicious activity

  • web:attack.mitre.org

    Sliver is an open source, cross-platform, red team command and control (C2) framework written in Golang. Sliver includes its own package manager, "armory," for staging and downloading additional tools and payloads to the primary C2 framework.

  • web:github.com

    Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. Sliver's implants support C2 over Mutual TLS (mTLS), WireGuard, HTTP (S), and DNS and are dynamically compiled with per-binary asymmetric encryption keys.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to VK9 Seecurity, Sliver is a Command and Control (C2) system made for penetration testers, red teams, and advanced persistent threats. It generates implants ( slivers ) that can run on virtually every architecture out there, and securely manage these connections through a central server. Sliver supports multiple callback protocols including DNS, TCP, and HTTP (S) to make egress simple ...

  • web:radicl.com

    We identified a two-stage malware operation: a Rust-compiled downloader that fetches and AES-128-CFB decrypts a second payload confirmed to be a modified build of Sliver , the open-source C2 framework. Both stages are staged inside a misconfigured cloud storage bucket belonging to an unrelated third party, and command-and-control runs behind Cloudflare Tunnel, concealing the operator's true ...

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL .

  • web:www.cybereason.com

    Sliver C2 implant is designed to be used as a second stage payload (not leveraged during the initial infection step) after the attacker has gained access to the target system using an initial infection vector such as for example - phishing, drive by download, exploitation of unpatched vulnerabilities to get deployed on the target system.

  • web:www.microsoft.com

    An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat.

  • web:www.microsoft.com

    Sliver also supports stagers—smaller payloads with few built-in features that are primarily intended to retrieve and launch a full implant. Stagers are used by many C2 frameworks to minimize the malicious code that's included in an initial payload (for example, in a phishing email).

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.