MB-9fbf6e1bd7ca3922c017491ef52ffa8c123084e231021e7610942f65303c86b2
high
📛 Threat Title
SalatStealer: big.exe
Description
File type: exe. Size: 3587584 bytes. Tags: SalatStealer, upx. Reporter: BlinkzSec. First seen: 2026-05-14 13:39:47.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
big.exe
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/big.exe
IOC database
- Type
- domain
- Value
big.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Extracted from Threat MB-f5286c639c299102c296f129dd23d814615f98e71d03f7853e43e901c400ff55
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/big.exe
hash_imphash
6ed4f5f04d62b18d96b26d6db7c18840
IOC database
- Type
- hash_imphash
- Value
6ed4f5f04d62b18d96b26d6db7c18840- First seen
- Last seen
- Attached to this threat
- Appears in
- 42 threats
- Description
- imphash of URLhaus payload f36467769f8a9e79…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
9fbf6e1bd7ca3922c017491ef52ffa8c123084e231021e7610942f65303c86b2
1 feed
IOC database
- Type
- hash_sha256
- Value
9fbf6e1bd7ca3922c017491ef52ffa8c123084e231021e7610942f65303c86b2- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- SalatStealer
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
8fe556ad69bf64e09c4b226e97e044873ff5b734
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8fe556ad69bf64e09c4b226e97e044873ff5b734
2 feeds
IOC database
- Type
- hash_sha1
- Value
8fe556ad69bf64e09c4b226e97e044873ff5b734- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8fe556ad69bf64e09c4b226e97e044873ff5b734
hash_md5
9c7dbb85224215cb694d41d0dbfdadf5
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9c7dbb85224215cb694d41d0dbfdadf5
2 feeds
IOC database
- Type
- hash_md5
- Value
9c7dbb85224215cb694d41d0dbfdadf5- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9c7dbb85224215cb694d41d0dbfdadf5
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 3587584 bytes. Tags: SalatStealer, upx. Reporter: BlinkzSec. First seen: 2026-05-14 13:39:47.
Remediations (10)
-
web:any.run
SalatStealer , also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.
-
web:blog.jrdioca.com
Reverse Engineering, Malware Analysis · 25 Jul 2025 Salat Stealer Summary This report analyzes a UPX-packed Windows executable file identified as a Salat Stealer. The malware collects the victim's keystrokes, system information, browser-stored credentials, cryptocurrency wallet data, and messaging applications data. It can also access the victim's webcam and microphone. It compresses the ...
-
web:blog.netmanageit.com
7. Mitigation Strategies and Conclusion Effective defense against Salat Stealer requires a multi-layered approach. Enterprises should enforce application whitelisting, deploy endpoint detection and response tools capable of identifying unusual UPX unpacking behavior, and monitor registry hives and scheduled tasks for unauthorized entries.
-
web:cybersecuritynews.com
Salat Stealer targets Windows, stealing browser logins and crypto wallets via fake cracks, cheats, and stealthy Go-based evasion.
-
web:darkatlas.io
Technical analysis of Salat Stealer, a Go-based RAT with resilient C2, credential theft, persistence, and remote control features.
-
web:gbhackers.com
A powerful new Windows malware family dubbed Salat Stealer, a Go-based Remote Access Trojan (RAT) that blends classic infostealing with a stealthy QUIC/WebSocket.
-
web:socprime.com
Salat Stealer is a Go-based RAT that steals credentials and crypto data while using QUIC, WebSocket, and TON for resilient C2
-
web:www.cyfirma.com
EXECUTIVE SUMMARY CYFIRMA has identified Salat Stealer (also known as WEB_RAT), a sophisticated Go-based infostealer targeting Windows systems. The malware exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques, including UPX packing, process masquerading, registry run keys, and scheduled tasks. Operated under a Malware ...
-
web:www.linkedin.com
Malware infection ( SalatStealer ) following a downloaded .crdownload file, renamed to taskhostw.exe, executed, followed by LSASS credential access/dumping and outbound communications consistent ...
-
web:www.pcrisk.com
Malware removal rarely necessitates formatting. What are the biggest issues that Salat malware can cause? The dangers posed by an infection depend on the malware's abilities and the cyber criminals' modus operandi. Salat is a stealer that can download victims' files, record audio/video, live-stream desktops, and perform other malicious activities.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.