logo

Threat Actors’ Toolkit: Leveraging Sliver, PoshC2 & Batch Scripts

ID: 7eb2e68f-5239-53de-823e-9092c33848bb

STIX ID: report--7eb2e68f-5239-53de-823e-9092c33848bb

Feed Name: The DFIR Report

Threat Score
78/100

Date Published: 2024-08-12

Date Updated: 2026-04-19

Author: editor

...
...

**Executive Summary:** This report analyzes two open directories (94.198.53.143 and 185.234.216.64) hosting batch scripts and binaries tied to PoshC2, Sliver, SystemBC and other tooling; the artifacts include scripts to disable AV, delete backups/shadow copies, enable RDP/backdoors, and deploy remote agents, and the authors provide IOCs, file hashes, MITRE mappings, and evidence of active C2 infrastructure observed through August 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.