TF-1932522
high
📛 Threat Title
Sliver: URL that delivers a malware payload http://myanmar001.xyz/implant.exe
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Sliver. Confidence: 95. First seen: 2026-09-25 00:41:52 UTC. Reporter: whack_sh. Tags: exe, sliver.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://myanmar001.xyz/implant.exe
IOC database
- Type
- url
- Value
http://myanmar001.xyz/implant.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that delivers a malware payload attributed to Sliver
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Sliver. Confidence: 95. First seen: 2026-09-25 00:41:52 UTC. Reporter: whack_sh. Tags: exe, sliver.
Remediations (10)
-
web:any.run
Sliver is a C2 framework that allows attackers to maintain access, control systems, and conduct further attacks while remaining undetected.
-
web:any.run
Online sandbox report for implant.exe, tagged as sliver , golang, verdict: Malicious activity
-
web:attack.mitre.org
Sliver is an open source, cross-platform, red team command and control (C2) framework written in Golang. Sliver includes its own package manager, "armory," for staging and downloading additional tools and payloads to the primary C2 framework.
-
web:github.com
Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. Sliver's implants support C2 over Mutual TLS (mTLS), WireGuard, HTTP (S), and DNS and are dynamically compiled with per-binary asymmetric encryption keys.
-
web:malpedia.caad.fkie.fraunhofer.de
According to VK9 Seecurity, Sliver is a Command and Control (C2) system made for penetration testers, red teams, and advanced persistent threats. It generates implants ( slivers ) that can run on virtually every architecture out there, and securely manage these connections through a central server. Sliver supports multiple callback protocols including DNS, TCP, and HTTP (S) to make egress simple ...
-
web:radicl.com
We identified a two-stage malware operation: a Rust-compiled downloader that fetches and AES-128-CFB decrypts a second payload confirmed to be a modified build of Sliver , the open-source C2 framework. Both stages are staged inside a misconfigured cloud storage bucket belonging to an unrelated third party, and command-and-control runs behind Cloudflare Tunnel, concealing the operator's true ...
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL .
-
web:www.cybereason.com
Sliver C2 implant is designed to be used as a second stage payload (not leveraged during the initial infection step) after the attacker has gained access to the target system using an initial infection vector such as for example - phishing, drive by download, exploitation of unpatched vulnerabilities to get deployed on the target system.
-
web:www.microsoft.com
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat.
-
web:www.microsoft.com
Sliver also supports stagers—smaller payloads with few built-in features that are primarily intended to retrieve and launch a full implant. Stagers are used by many C2 frameworks to minimize the malicious code that's included in an initial payload (for example, in a phishing email).
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.