s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-9fbf6e1bd7ca3922c017491ef52ffa8c123084e231021e7610942f65303c86b2 high

📛 Threat Title

SalatStealer: big.exe

Category: SalatStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 3587584 bytes. Tags: SalatStealer, upx. Reporter: BlinkzSec. First seen: 2026-05-14 13:39:47.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain big.exe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/big.exe

IOC database

Type
domain
Value
big.exe
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Extracted from Threat MB-f5286c639c299102c296f129dd23d814615f98e71d03f7853e43e901c400ff55

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/big.exe

hash_imphash 6ed4f5f04d62b18d96b26d6db7c18840

IOC database

Type
hash_imphash
Value
6ed4f5f04d62b18d96b26d6db7c18840
First seen
Last seen
Attached to this threat
Appears in
42 threats
Description
imphash of URLhaus payload f36467769f8a9e79…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 9fbf6e1bd7ca3922c017491ef52ffa8c123084e231021e7610942f65303c86b2 1 feed

IOC database

Type
hash_sha256
Value
9fbf6e1bd7ca3922c017491ef52ffa8c123084e231021e7610942f65303c86b2
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
SalatStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 8fe556ad69bf64e09c4b226e97e044873ff5b734 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8fe556ad69bf64e09c4b226e97e044873ff5b734
2 feeds

IOC database

Type
hash_sha1
Value
8fe556ad69bf64e09c4b226e97e044873ff5b734
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8fe556ad69bf64e09c4b226e97e044873ff5b734

hash_md5 9c7dbb85224215cb694d41d0dbfdadf5 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9c7dbb85224215cb694d41d0dbfdadf5
2 feeds

IOC database

Type
hash_md5
Value
9c7dbb85224215cb694d41d0dbfdadf5
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9c7dbb85224215cb694d41d0dbfdadf5

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 3587584 bytes. Tags: SalatStealer, upx. Reporter: BlinkzSec. First seen: 2026-05-14 13:39:47.

Remediations (10)

  • web:any.run

    SalatStealer , also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.

  • web:blog.jrdioca.com

    Reverse Engineering, Malware Analysis · 25 Jul 2025 Salat Stealer Summary This report analyzes a UPX-packed Windows executable file identified as a Salat Stealer. The malware collects the victim's keystrokes, system information, browser-stored credentials, cryptocurrency wallet data, and messaging applications data. It can also access the victim's webcam and microphone. It compresses the ...

  • web:blog.netmanageit.com

    7. Mitigation Strategies and Conclusion Effective defense against Salat Stealer requires a multi-layered approach. Enterprises should enforce application whitelisting, deploy endpoint detection and response tools capable of identifying unusual UPX unpacking behavior, and monitor registry hives and scheduled tasks for unauthorized entries.

  • web:cybersecuritynews.com

    Salat Stealer targets Windows, stealing browser logins and crypto wallets via fake cracks, cheats, and stealthy Go-based evasion.

  • web:darkatlas.io

    Technical analysis of Salat Stealer, a Go-based RAT with resilient C2, credential theft, persistence, and remote control features.

  • web:gbhackers.com

    A powerful new Windows malware family dubbed Salat Stealer, a Go-based Remote Access Trojan (RAT) that blends classic infostealing with a stealthy QUIC/WebSocket.

  • web:socprime.com

    Salat Stealer is a Go-based RAT that steals credentials and crypto data while using QUIC, WebSocket, and TON for resilient C2

  • web:www.cyfirma.com

    EXECUTIVE SUMMARY CYFIRMA has identified Salat Stealer (also known as WEB_RAT), a sophisticated Go-based infostealer targeting Windows systems. The malware exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques, including UPX packing, process masquerading, registry run keys, and scheduled tasks. Operated under a Malware ...

  • web:www.linkedin.com

    Malware infection ( SalatStealer ) following a downloaded .crdownload file, renamed to taskhostw.exe, executed, followed by LSASS credential access/dumping and outbound communications consistent ...

  • web:www.pcrisk.com

    Malware removal rarely necessitates formatting. What are the biggest issues that Salat malware can cause? The dangers posed by an infection depend on the malware's abilities and the cyber criminals' modus operandi. Salat is a stealer that can download victims' files, record audio/video, live-stream desktops, and perform other malicious activities.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.