s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932524 high

📛 Threat Title

SalatStealer: URL that delivers a malware payload https://rmp.computer/123.exe

Category: SalatStealer Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: SalatStealer. Confidence: 95. First seen: 2026-09-25 00:41:56 UTC. Reporter: whack_sh. Tags: exe, SalatStealer, stealer, upx.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url https://rmp.computer/123.exe UrlVoid 2 / 36

IOC database

Type
url
Value
https://rmp.computer/123.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that delivers a malware payload attributed to SalatStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: SalatStealer. Confidence: 95. First seen: 2026-09-25 00:41:56 UTC. Reporter: whack_sh. Tags: exe, SalatStealer, stealer, upx.

Remediations (10)

  • web:any.run

    SalatStealer , also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware - as -a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.

  • web:bazaar.abuse.ch

    Malware samples associated with tag SalatStealer MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with SalatStealer . Database ...

  • web:blog.netmanageit.com

    The malware uses UPX packing, process masquerading, registry run keys, and scheduled tasks for persistence and evasion. Operated under a Malware - as -a-Service model by Russian-speaking actors, it leverages resilient C2 infrastructure. The stealer targets multiple browsers, cryptocurrency wallets, and Telegram sessions.

  • web:cybersecuritynews.com

    Salat Stealer targets Windows, stealing browser logins and crypto wallets via fake cracks, cheats, and stealthy Go-based evasion.

  • web:research.splunk.com

    Updated Date: 2026-05-12 ID: d4f2a1b3-5c6e-4d7f-8e9a-1b2c3d4e5f60 Author: Teoderick Contreras, Splunk Product: Splunk Enterprise Security Description Salat Stealer is a Windows-based information-stealing malware associated with the UAC-0252 threat activity group, which has been observed delivering it alongside the ShadowSniff credential harvester. Once deployed, Salat Stealer targets sensitive ...

  • web:socprime.com

    Summary Salat Stealer is a Go-based remote access trojan that functions as a full-featured post-exploitation framework. It supports multiple communication channels, including WebSocket, HTTP/2, HTTP/3, and QUIC, giving operators flexible and resilient command-and-control options. The malware also includes broad credential theft capabilities, targeting browser data, cryptocurrency wallets ...

  • web:www.cyfirma.com

    A critical component of this MaaS ecosystem is its reliance on mainstream platforms for malware delivery. Attackers exploit YouTube through fake or compromised accounts to advertise game cheats, software cracks, and bots. Links embedded in video descriptions redirect victims to file-sharing services hosting malware -laden archives.

  • web:www.dexpose.io

    SalatStealer is a stealthy and persistent malware designed to steal sensitive data while evading detection. By harvesting credentials, exfiltrating files, and enabling real-time surveillance, it poses severe risks to victims, including financial loss, identity theft, and privacy breaches.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.splunk.com

    The archive password, 111, was displayed on the webpage during analysis. Execution of Xeno.exe resulted in the drop of two executables: soa.exe, a secondary self-extracting file used to install the legitimate Xeno Executor application, and wios.exe, which contained the actual Salat Stealer payload bundled with the installer.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.