Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Sliver

74
Global rank
97 infographic chevron month
Month rank
93 infographic chevron week
Week rank

Sliver is an open-source command-and-control (C2) framework that has been increasingly adopted by threat actors as an alternative to tools like Cobalt Strike. Developed by security firm Bishop Fox, Sliver was initially intended for legitimate security testing and red teaming exercises. However, its robust features and open-source nature have made it attractive to malicious actors seeking to control compromised systems.

C2 Framework
Type
Unknown
Origin
3 June, 2019
First seen
17 September, 2026
Last seen

How to analyze Sliver with ANY.RUN

C2 Framework
Type
Unknown
Origin
3 June, 2019
First seen
17 September, 2026
Last seen

IOCs

IP addresses
135.181.128.167
23.59.18.102
40.126.31.67
150.171.109.194
2.16.204.144
48.192.1.65
2.16.164.88
52.123.243.205
23.11.41.157
2.23.246.9
150.171.109.101
150.171.27.11
2.16.204.158
104.18.23.222
172.211.123.248
74.178.240.51
48.209.133.15
150.171.109.100
150.171.28.11
74.178.76.128
Hashes
439c5f4128e6485bcbbcff7abdce9a40716ea301b5489c8918751182e131d050
8232c450f967d7f2f22c54582f0667f4c033ae62e6d450ff8a35c47486249443
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
f51a7acfffec56d6751561966d947d3fd199b74528c07dabdcf5fcb33d5b2e85
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
7852fce59c67ddf1d6b8b997eaa1adfac004a9f3a91c37295de9223674011fba
2445cad863be47bb1c15b57a4960b7b0d01864e63cdfde6395f3b2689dc1444b
ff702ca753a7e3b75f9d9850cc9343e28e8d60f8005a2c955c8ac2105532b2c9
af889c1deb6f9248961c2f8ba4307a8206d7163616a5b7455d17cead00068317
728d8cbd71263680a4e41399db65b3f2b8175d50ca630afd30643ced9ffe831f
22bc37b47ce8a832f39701641dc358357676e9be187a93a4c5d4b016e29238ae
cc3e9077fcc9bd0dfc5dd3924c6c48b8345f32cee24fccc508c279f45b2abe61
14895bf43ce9b76c0ff4f9aef93dbe8bb6ca496894870cf0c007b189e0cef00e
7ccc7b17bfe01c3c7dd33eff8f80d0b57fc9b175815e766c9c1c1e893725e20f
6c69ce0fe6fab14f1990a320d704fee362c175c00eb6c9224aa6f41108918ca6
5f4229d18e5606330146ee13bdf726e10c1e06cbb15368c47f1ae68abe9ce4ba
ec78ddd4ccf32b5d76ec701a20167c3fbd146d79a505e4fb0421fc1e5cf4aa63
41ce6a7b18364efecced0419b42165d4f86c43643bbe1043014d4142cf86186a
Domains
nexusrules.officeapps.live.com
xpaywalletcdn.azureedge.net
msedge.b.tlu.dl.delivery.mp.microsoft.com
edge.microsoft.com
edge-consumer-static.azureedge.net
login.live.com
ecs.office.com
static.edge.microsoftapp.net
api.edgeoffer.microsoft.com
clients2.googleusercontent.com
google.com
config.edge.skype.com
update.googleapis.com
edge-cloud-resource-static.azureedge.net
filebin.net
go.microsoft.com
activation-v2.sls.microsoft.com
crl.microsoft.com
slscr.update.microsoft.com
www.bing.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:xf3k3jxcvhpgaxyz7fomvpnv7bqz7qsiechyxx3oei4&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d272%2526e%253d1
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://update.googleapis.com/service/update2/json?cup2key=14:hyqyt7o16hkaxosh_zhx31tnmw0vvsd0kg7hihwep8c&cup2hreq=3152d008c8081b028388418beaad4e78197ea22956a7ad094944fecaf0abb2da
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
https://clients2.googleusercontent.com/crx/blobs/abe5cl52ck7wwbndbvvaem8oys3yhboz1h4zjji-spceoodztoqtbav4glxcdddxfkjcfz5qxdftce2lflmfl4fmgxvilhkmrudcuedenzrbmgjjiqxwnwfy8qwxmtkglheaxlka5bx6yvrdaanj1smxvmii4akl_ln2/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_110_1_0.crx
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1292
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1586
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3183
comments 0

What is Sliver malware?

Sliver is an open-source command-and-control framework designed for adversary emulation and red teaming. First released in 2019 by Bishop Fox, it has been adopted by both security professionals and threat actors.

Malicious users leverage Sliver to establish control over compromised systems, facilitating activities such as data exfiltration, lateral movement, and deployment of additional malware.

Its distribution methods include phishing emails, malicious documents, drive-by downloads, and exploitation of vulnerabilities.

Key technical features encompass cross-platform compatibility, support for multiple communication protocols, and capabilities like process injection and token manipulation.

To see how Sliver operates inside a secure environment, you can use tools such as ANY.RUN’s sandbox.

Sliver C2 in ANY.RUN sandbox Sliver analyzed inside ANY.RUN sandbox

One of the standout features of Sliver C2 is its accessibility. Being open-source, it's easy to download and set up, with compatibility across major operating systems like MacOS, Windows, and Linux. This cross-platform nature ensures that users can implement Sliver C2 in a variety of environments.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Sliver malware technical details

Sliver malware generates implants, commonly referred to as ‘slivers’, which consist of malicious code designed for remote control of compromised devices.

When a sliver is successfully deployed on a target system, it facilitates a communication channel with the central C2 server. This connection is crucial, as it enables the operator to send commands and receive data from the compromised device.

Sliver C2 supports various protocols for managing these connections, including Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS.

Sliver’s primary functionalities include:

  • Creating malicious payloads tailored to specific operating systems, which are then delivered through various vectors such as phishing emails or malicious documents.
  • Once the target executes the payload, it establishes a connection back to the Sliver C2 server, granting the attacker control over the compromised system.
  • Communicates with the C2 server at predetermined intervals using encrypted channels, aiding in evading detection.
  • Performs post-exploitation activities, such as privilege escalation, establishing persistence mechanisms, lateral movement within the network, and credential harvesting.
  • Uses techniques such as log deletion, obfuscation. The use of memory-only payloads are employed to minimize forensic evidence and hinder detection.
  • May close the C2 connection, leave backdoors for future access, or pivot to new targets to repeat the attack cycle.

Sliver malware execution process

To see how Sliver operates, let’s upload its sample to the ANY.RUN sandbox.

The execution chain of Sliver typically follows these steps: Initial access vector involves payload generation by creating a malicious payload for the target OS, delivered via phishing, malicious documents, drive-by downloads, or vulnerability exploitation.

Payload execution occurs when the target runs the payload, establishing a foothold and connecting back to the Sliver C2 server.

Command and Control (C2) begins with the infected machine beaconing to the C2 server at set intervals, using encrypted channels to avoid detection.

Sliver Suricata in ANY.RUN sandbox Suricata rule triggered by Sliver inside ANY.RUN’s sandbox

Post-exploitation activities include privilege escalation using built-in or custom tools, persistence through registry modifications or scheduled tasks, lateral movement within the network, and credential harvesting.

Data collection and exfiltration involve identifying valuable data and transmitting it back to the attacker's infrastructure, often encrypted.

Covering tracks includes log deletion and anti-forensics techniques like obfuscation and memory-only payloads. The termination or pivoting phase involves closing the C2 connection or leaving backdoors for future access and potentially pivoting to new targets to repeat the execution chain.

Sliver malware distribution methods

Attackers distribute Sliver through various methods, including:

  • Phishing emails: Sending emails with malicious attachments or links that, when opened, execute the Sliver payload.
  • Malicious documents: Embedding macros or exploits within documents that, upon execution, deploy Sliver.
  • Drive-by downloads: Compromising websites to automatically download and execute Sliver when visited.

Gathering threat intelligence on Sliver malware

To obtain up-to-date intelligence on Sliver, utilize the Threat Intelligence Lookup service.

This platform gives you access to an extensive database enriched with data from countless malware analysis sessions executed in the ANY.RUN sandbox. With over 40 customizable search parameters at your disposal, you can efficiently uncover important information on various threats, including details such as IP addresses, domains, file names, and process artifacts.

Sliver TI Lookup in ANY.RUN sandbox TI Lookup reveals key threat context related to Sliver C2

For instance, to retrieve intelligence on Sliver, you can either search for its specific threat name or utilize related artifacts. By creating a query like threatName:"sliver" and destinationIP:"", the TI Lookup will provide you with all relevant samples and sandbox analyses associated with this particular malware.

Get a 14-day free trial of Threat Intelligence Lookup along with the ANY.RUN sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Sliver’s open-source nature and cross-platform compatibility further enhance its appeal to threat actors. To defend against such threats, it’s crucial to integrate advanced analysis tools that can proactively identify and mitigate suspicious activities.

ANY.RUN is an interactive malware analysis sandbox that enables real-time examination of suspicious files and URLs. Its user-friendly interface and comprehensive analysis capabilities allow security professionals to dissect malware behavior, understand its impact, and develop effective countermeasures.

Sign up for a free account with ANY.RUN to stay ahead of emerging threats like Sliver

HAVE A LOOK AT

Phishing kit screenshot
Phishing kit
tycoon evilproxy sneaky2fa
Phishing kits are pre-packaged sets of malicious tools designed to make it easy for cybercriminals to launch phishing attacks. These kits replicate legitimate websites, steal credentials, and often include backend infrastructure for managing stolen data.
Read More
Salty 2FA screenshot
Salty 2FA
salty2fa
Salty 2FA is a sophisticated Phishing-as-a-Service (PhaaS) framework tailored to hijack user sessions, steal credentials, and gain unauthorized access to corporate systems. Delivered primarily via targeted emails, this kit employs multi-stage evasion tactics, making it a stealthy tool for cybercriminals aiming at high-value enterprise accounts.
Read More
Cerber screenshot
Cerber
cerber
Cerber is a Ransomware-as-a-Service (RaaS) that appeared in 2016, spread quickly and has been evolving since. It became well-known for its file encryption, offline capabilities, and sophisticated evasion techniques. It primarily targets enterprises, financial institutions, and government entities, encrypting their data and demanding ransom payments in Bitcoin. It also targets everyday users encrypting personal files (photos, documents) with the risk of their permanent loss.
Read More
SolarisLoader screenshot
SolarisLoader
solaris
SolarisLoader is a malware loader designed to neutralize security infrastructure before deploying high-risk secondary payloads. It utilizes a "Bring Your Own Vulnerable Driver" technique to gain kernel-level access and terminate antivirus processes. To remain undetected, the malware patches internal Windows monitoring interfaces and isolates the machine from security updates. Finally, it establishes a resilient three-layer persistence mechanism involving scheduled tasks, registry backups, and a watchdog component.
Read More
zgRAT screenshot
zgRAT
zgrat
zgRAT is a malware known for its ability to infect systems and exfiltrate sensitive data to command-and-control (C2) servers. It is primarily distributed through loader malware, as well as phishing emails. zgRAT employs various advanced techniques, including process injection and code obfuscation, to evade detection and maintain persistence on infected systems. The malware can also spread via USB drives and uses popular messaging platforms like Telegram and Discord for data exfiltration.
Read More
SalatStealer screenshot
SalatStealer
salatstealer
SalatStealer, also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.
Read More