s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-1df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8 high

📛 Threat Title

SalatStealer: 1df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8.exe

Category: SalatStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 3593216 bytes. Tags: exe, salat, salatstealer, stealer, upx. Reporter: Kejult. First seen: 2026-09-25 11:14:28.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 6ed4f5f04d62b18d96b26d6db7c18840

IOC database

Type
hash_imphash
Value
6ed4f5f04d62b18d96b26d6db7c18840
First seen
Last seen
Attached to this threat
Appears in
87 threats
Description
imphash of URLhaus payload f36467769f8a9e79…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 1df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8 VT 48 / 75

IOC database

Type
hash_sha256
Value
1df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
SalatStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 48 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R734522
Alibaba malicious TrojanBanker:Win32/SalatStealer.598c476e
alibabacloud malicious Trojan:Multi/Rozena.SS
ALYac malicious Dump:Generic.Dacic.18086.87F8CDFA
APEX malicious Malicious
Arcabit malicious Dump:Generic.Dacic.18086.87F8CDFA
Avast malicious Win32:SalatStealer-A [Pws]
AVG malicious Win32:SalatStealer-A [Pws]
BitDefender malicious Dump:Generic.Dacic.18086.87F8CDFA
Bkav malicious W32.Malware.51335C8A
CrowdStrike malicious win/malicious_confidence_100% (D)
CTX malicious exe.unknown.dacic
Cylance malicious Unsafe
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Salat.389
Elastic malicious malicious (moderate confidence)
Emsisoft malicious Dump:Generic.Dacic.18086.87F8CDFA (B)
ESET-NOD32 malicious WinGo/Agent_AGen.XS trojan
Fortinet malicious W32/Agent.XS!tr
GData malicious Dump:Generic.Dacic.18086.87F8CDFA
Google malicious Detected
huorong malicious Trojan/Agent.e!crit
Ikarus malicious Trojan.Win32.SalatStealer
K7AntiVirus malicious Trojan ( 005ce1d91 )
K7GW malicious Trojan ( 005ce1d91 )
Kaspersky malicious UDS:DangerousObject.Multi.Generic
Kingsoft malicious Win32.Troj.Unknown.a
Lionic malicious Trojan.Win32.Dacic.4!c
Malwarebytes malicious Trojan.MalPack.UPX
MaxSecure malicious Trojan.Malware.300983.susgen
McAfeeD malicious Real Protect-LS!257BF3CC6BC4
Microsoft malicious Trojan:Win32/Wacatac.B!ml
MicroWorld-eScan malicious Dump:Generic.Dacic.18086.87F8CDFA
Paloalto malicious generic.ml
Rising malicious Stealer.Salat!1.13A22 (CLOUD)
Sangfor malicious Infostealer.Win32.Agent.Veaa
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious Trojan-JBNR!A2602760FF05
Sophos malicious Troj/Salat-B
Symantec malicious ML.Attribute.HighConfidence
TACHYON malicious Trojan/W32.Agent.12571648.C
Tencent malicious Trojan.Win32.Stealer.16001830
Trapmine malicious malicious.high.ml.score
TrellixENS malicious Artemis!257BF3CC6BC4
VIPRE malicious Dump:Generic.Dacic.18086.87F8CDFA
Webroot malicious W32.Malware.gen
ZoneAlarm malicious Troj/Salat-B

Details From VirusTotal

Basic Properties
MD5257bf3cc6bc44505dd1f3bba6eb2e1c6
SHA-185445860a44f5eec61599eb42a76350c1409e226
SHA-2561df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8
VHash03603e0f7d1bz4!z
SSDEEP49152:J+TZ9CEuT1oZbKR/loU0PndiSxuEhQxqenE/eCCJ/cTStu8O7YDPTqPilr17xDwp:E/9uKwL0PdiSwEm1JaP8EYD7qP2syI0
TLSHT166F533C28BC0F59AC6239EB06B871C93B6B5F8CBE45E1B7544FCA81A83C497E1985471
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
File size3.4 MB
History
First seen on VirusTotal2026-09-25 09:45 UTC
Last submission2026-09-25 11:53 UTC
Last analysis2026-09-25 11:53 UTC
Last modified on VirusTotal2026-09-25 13:54 UTC
Known Names
  • hmr52cw8q.exe
  • 9fr18d8.exe
  • updater_rFxWppLs.exe
hash_sha1 85445860a44f5eec61599eb42a76350c1409e226 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/85445860a44f5eec61599eb42a76350c1409e226

IOC database

Type
hash_sha1
Value
85445860a44f5eec61599eb42a76350c1409e226
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/85445860a44f5eec61599eb42a76350c1409e226

hash_md5 257bf3cc6bc44505dd1f3bba6eb2e1c6 VT 48 / 75

IOC database

Type
hash_md5
Value
257bf3cc6bc44505dd1f3bba6eb2e1c6
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 48 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R734522
Alibaba malicious TrojanBanker:Win32/SalatStealer.598c476e
alibabacloud malicious Trojan:Multi/Rozena.SS
ALYac malicious Dump:Generic.Dacic.18086.87F8CDFA
APEX malicious Malicious
Arcabit malicious Dump:Generic.Dacic.18086.87F8CDFA
Avast malicious Win32:SalatStealer-A [Pws]
AVG malicious Win32:SalatStealer-A [Pws]
BitDefender malicious Dump:Generic.Dacic.18086.87F8CDFA
Bkav malicious W32.Malware.51335C8A
CrowdStrike malicious win/malicious_confidence_100% (D)
CTX malicious exe.unknown.dacic
Cylance malicious Unsafe
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Salat.389
Elastic malicious malicious (moderate confidence)
Emsisoft malicious Dump:Generic.Dacic.18086.87F8CDFA (B)
ESET-NOD32 malicious WinGo/Agent_AGen.XS trojan
Fortinet malicious W32/Agent.XS!tr
GData malicious Dump:Generic.Dacic.18086.87F8CDFA
Google malicious Detected
huorong malicious Trojan/Agent.e!crit
Ikarus malicious Trojan.Win32.SalatStealer
K7AntiVirus malicious Trojan ( 005ce1d91 )
K7GW malicious Trojan ( 005ce1d91 )
Kaspersky malicious UDS:DangerousObject.Multi.Generic
Kingsoft malicious Win32.Troj.Unknown.a
Lionic malicious Trojan.Win32.Dacic.4!c
Malwarebytes malicious Trojan.MalPack.UPX
MaxSecure malicious Trojan.Malware.300983.susgen
McAfeeD malicious Real Protect-LS!257BF3CC6BC4
Microsoft malicious Trojan:Win32/Wacatac.B!ml
MicroWorld-eScan malicious Dump:Generic.Dacic.18086.87F8CDFA
Paloalto malicious generic.ml
Rising malicious Stealer.Salat!1.13A22 (CLOUD)
Sangfor malicious Infostealer.Win32.Agent.Veaa
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious Trojan-JBNR!A2602760FF05
Sophos malicious Troj/Salat-B
Symantec malicious ML.Attribute.HighConfidence
TACHYON malicious Trojan/W32.Agent.12571648.C
Tencent malicious Trojan.Win32.Stealer.16001830
Trapmine malicious malicious.high.ml.score
TrellixENS malicious Artemis!257BF3CC6BC4
VIPRE malicious Dump:Generic.Dacic.18086.87F8CDFA
Webroot malicious W32.Malware.gen
ZoneAlarm malicious Troj/Salat-B

Details From VirusTotal

Basic Properties
MD5257bf3cc6bc44505dd1f3bba6eb2e1c6
SHA-185445860a44f5eec61599eb42a76350c1409e226
SHA-2561df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8
VHash03603e0f7d1bz4!z
SSDEEP49152:J+TZ9CEuT1oZbKR/loU0PndiSxuEhQxqenE/eCCJ/cTStu8O7YDPTqPilr17xDwp:E/9uKwL0PdiSwEm1JaP8EYD7qP2syI0
TLSHT166F533C28BC0F59AC6239EB06B871C93B6B5F8CBE45E1B7544FCA81A83C497E1985471
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
File size3.4 MB
History
First seen on VirusTotal2026-09-25 09:45 UTC
Last submission2026-09-25 11:53 UTC
Last analysis2026-09-25 11:53 UTC
Last modified on VirusTotal2026-09-25 13:54 UTC
Known Names
  • hmr52cw8q.exe
  • 9fr18d8.exe
  • updater_rFxWppLs.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 3593216 bytes. Tags: exe, salat, salatstealer, stealer, upx. Reporter: Kejult. First seen: 2026-09-25 11:14:28.

Remediations (10)

  • web:any.run

    SalatStealer malware, a Go-based infostealer, targets browser credentials, cryptocurrency wallets, and Telegram sessions using advanced evasion and persistence techniques.

  • web:bazaar.abuse.ch

    SalatStealer malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as SalatStealer . Database Entry

  • web:boteraser.com

    🛡️ Mitigation To defend against SalatStealer , organizations should block execution of unsigned binaries downloaded from the internet, enable Windows Defender real-time protection with cloud-delivered protection, and implement application control policies that prevent unauthorized scripts and executables from running.

  • web:cybersecuritynews.com

    Salat Stealer targets Windows, stealing browser logins and crypto wallets via fake cracks, cheats, and stealthy Go-based evasion.

  • web:socprime.com

    Salat Stealer is a Go-based remote access trojan that functions as a full-featured post-exploitation framework. It supports multiple communication channels, including WebSocket, HTTP/2, HTTP/3, and QUIC, giving operators flexible and resilient command-and-control options.

  • web:www.broadcom.com

    Salat Stealer, a Go-based infostealer offered under a Malware-as-a-Service model, has been reported by Cyfirma. Likely operated by Russian-speaking actors, the malware employs layered persistence techniques, including registry Run keys, scheduled tasks, process masquerading and modifications to Windows Defender exclusions to evade detection.

  • web:www.cyfirma.com

    CONCLUSION Salat Stealer exemplifies the growing sophistication of Malware-as-a-Service ecosystems, blending advanced persistence, evasion, and data theft techniques with resilient C2 operations. Its ability to harvest browser credentials, cryptocurrency assets, and session data poses significant risks to individuals and enterprises alike.

  • web:www.dexpose.io

    SalatStealer is a stealthy and persistent malware designed to steal sensitive data while evading detection. By harvesting credentials, exfiltrating files, and enabling real-time surveillance, it poses severe risks to victims, including financial loss, identity theft, and privacy breaches.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.pcrisk.com

    Malware removal rarely necessitates formatting. What are the biggest issues that Salat malware can cause? The dangers posed by an infection depend on the malware's abilities and the cyber criminals' modus operandi. Salat is a stealer that can download victims' files, record audio/video, live-stream desktops, and perform other malicious activities.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.