Skip to content
Multiple Sliver C2 Instances Detected on Port 31337

Multiple Sliver C2 Instances Detected on Port 31337

First seen 13 Sep 2026, 00:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 13, 2026 at 00:41 UTC
  • Multiple Sliver C2 servers detected on port 31337.
  • Ten distinct IP addresses reported, with potential for false positives.
  • Urgent validation recommended for affected systems.

On September 12, 2026, RedPacket Security reported the detection of multiple Sliver Command and Control (C2) servers operating on port 31337. The IP addresses identified include 103.227.225.194, 130.94.105.104, 38.76.215.245, 40.90.235.75, 103.253.42.34, 169.58.252.86, 45.38.20.151, 104.253.79.117, 129.226.150.240, and 192.155.92.211. The reports emphasize that the detections may be false positives and urge users to conduct their own validations. The potential impact of these detections is currently unclear, as no specific vulnerabilities or exploitation methods have been confirmed. Security professionals are advised to monitor these IP addresses and assess their network traffic for any unusual activity. The situation remains fluid, with ongoing analysis required to determine the legitimacy of these C2 detections.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-12
Multiple Sliver C2 detections reported
RedPacket Security identified ten IP addresses associated with Sliver C2 servers on port 31337.
Redpacketsecurity
2026-09-12
Warning issued for potential false positives
RedPacket Security cautioned that detections may not be accurate and advised further validation.
Redpacketsecurity

More articles in this cluster (10)

Following this threat?

Track Sliver in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed