MB-1df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8
high
📛 Threat Title
SalatStealer: 1df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8.exe
Description
File type: exe. Size: 3593216 bytes. Tags: exe, salat, salatstealer, stealer, upx. Reporter: Kejult. First seen: 2026-09-25 11:14:28.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
6ed4f5f04d62b18d96b26d6db7c18840
IOC database
- Type
- hash_imphash
- Value
6ed4f5f04d62b18d96b26d6db7c18840- First seen
- Last seen
- Attached to this threat
- Appears in
- 87 threats
- Description
- imphash of URLhaus payload f36467769f8a9e79…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
1df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8
VT 48 / 75
IOC database
- Type
- hash_sha256
- Value
1df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- SalatStealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 48 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.R734522 |
| Alibaba | malicious | TrojanBanker:Win32/SalatStealer.598c476e |
| alibabacloud | malicious | Trojan:Multi/Rozena.SS |
| ALYac | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| APEX | malicious | Malicious |
| Arcabit | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| Avast | malicious | Win32:SalatStealer-A [Pws] |
| AVG | malicious | Win32:SalatStealer-A [Pws] |
| BitDefender | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| Bkav | malicious | W32.Malware.51335C8A |
| CrowdStrike | malicious | win/malicious_confidence_100% (D) |
| CTX | malicious | exe.unknown.dacic |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 100) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Salat.389 |
| Elastic | malicious | malicious (moderate confidence) |
| Emsisoft | malicious | Dump:Generic.Dacic.18086.87F8CDFA (B) |
| ESET-NOD32 | malicious | WinGo/Agent_AGen.XS trojan |
| Fortinet | malicious | W32/Agent.XS!tr |
| GData | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| malicious | Detected |
|
| huorong | malicious | Trojan/Agent.e!crit |
| Ikarus | malicious | Trojan.Win32.SalatStealer |
| K7AntiVirus | malicious | Trojan ( 005ce1d91 ) |
| K7GW | malicious | Trojan ( 005ce1d91 ) |
| Kaspersky | malicious | UDS:DangerousObject.Multi.Generic |
| Kingsoft | malicious | Win32.Troj.Unknown.a |
| Lionic | malicious | Trojan.Win32.Dacic.4!c |
| Malwarebytes | malicious | Trojan.MalPack.UPX |
| MaxSecure | malicious | Trojan.Malware.300983.susgen |
| McAfeeD | malicious | Real Protect-LS!257BF3CC6BC4 |
| Microsoft | malicious | Trojan:Win32/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| Paloalto | malicious | generic.ml |
| Rising | malicious | Stealer.Salat!1.13A22 (CLOUD) |
| Sangfor | malicious | Infostealer.Win32.Agent.Veaa |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | Trojan-JBNR!A2602760FF05 |
| Sophos | malicious | Troj/Salat-B |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TACHYON | malicious | Trojan/W32.Agent.12571648.C |
| Tencent | malicious | Trojan.Win32.Stealer.16001830 |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | Artemis!257BF3CC6BC4 |
| VIPRE | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| Webroot | malicious | W32.Malware.gen |
| ZoneAlarm | malicious | Troj/Salat-B |
Details From VirusTotal
Basic Properties
| MD5 | 257bf3cc6bc44505dd1f3bba6eb2e1c6 |
| SHA-1 | 85445860a44f5eec61599eb42a76350c1409e226 |
| SHA-256 | 1df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8 |
| VHash | 03603e0f7d1bz4!z |
| SSDEEP | 49152:J+TZ9CEuT1oZbKR/loU0PndiSxuEhQxqenE/eCCJ/cTStu8O7YDPTqPilr17xDwp:E/9uKwL0PdiSwEm1JaP8EYD7qP2syI0 |
| TLSH | T166F533C28BC0F59AC6239EB06B871C93B6B5F8CBE45E1B7544FCA81A83C497E1985471 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| File size | 3.4 MB |
History
| First seen on VirusTotal | 2026-09-25 09:45 UTC |
| Last submission | 2026-09-25 11:53 UTC |
| Last analysis | 2026-09-25 11:53 UTC |
| Last modified on VirusTotal | 2026-09-25 13:54 UTC |
Known Names
hmr52cw8q.exe9fr18d8.exeupdater_rFxWppLs.exe
hash_sha1
85445860a44f5eec61599eb42a76350c1409e226
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/85445860a44f5eec61599eb42a76350c1409e226
IOC database
- Type
- hash_sha1
- Value
85445860a44f5eec61599eb42a76350c1409e226- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/85445860a44f5eec61599eb42a76350c1409e226
hash_md5
257bf3cc6bc44505dd1f3bba6eb2e1c6
VT 48 / 75
IOC database
- Type
- hash_md5
- Value
257bf3cc6bc44505dd1f3bba6eb2e1c6- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 48 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.R734522 |
| Alibaba | malicious | TrojanBanker:Win32/SalatStealer.598c476e |
| alibabacloud | malicious | Trojan:Multi/Rozena.SS |
| ALYac | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| APEX | malicious | Malicious |
| Arcabit | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| Avast | malicious | Win32:SalatStealer-A [Pws] |
| AVG | malicious | Win32:SalatStealer-A [Pws] |
| BitDefender | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| Bkav | malicious | W32.Malware.51335C8A |
| CrowdStrike | malicious | win/malicious_confidence_100% (D) |
| CTX | malicious | exe.unknown.dacic |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 100) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Salat.389 |
| Elastic | malicious | malicious (moderate confidence) |
| Emsisoft | malicious | Dump:Generic.Dacic.18086.87F8CDFA (B) |
| ESET-NOD32 | malicious | WinGo/Agent_AGen.XS trojan |
| Fortinet | malicious | W32/Agent.XS!tr |
| GData | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| malicious | Detected |
|
| huorong | malicious | Trojan/Agent.e!crit |
| Ikarus | malicious | Trojan.Win32.SalatStealer |
| K7AntiVirus | malicious | Trojan ( 005ce1d91 ) |
| K7GW | malicious | Trojan ( 005ce1d91 ) |
| Kaspersky | malicious | UDS:DangerousObject.Multi.Generic |
| Kingsoft | malicious | Win32.Troj.Unknown.a |
| Lionic | malicious | Trojan.Win32.Dacic.4!c |
| Malwarebytes | malicious | Trojan.MalPack.UPX |
| MaxSecure | malicious | Trojan.Malware.300983.susgen |
| McAfeeD | malicious | Real Protect-LS!257BF3CC6BC4 |
| Microsoft | malicious | Trojan:Win32/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| Paloalto | malicious | generic.ml |
| Rising | malicious | Stealer.Salat!1.13A22 (CLOUD) |
| Sangfor | malicious | Infostealer.Win32.Agent.Veaa |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | Trojan-JBNR!A2602760FF05 |
| Sophos | malicious | Troj/Salat-B |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TACHYON | malicious | Trojan/W32.Agent.12571648.C |
| Tencent | malicious | Trojan.Win32.Stealer.16001830 |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | Artemis!257BF3CC6BC4 |
| VIPRE | malicious | Dump:Generic.Dacic.18086.87F8CDFA |
| Webroot | malicious | W32.Malware.gen |
| ZoneAlarm | malicious | Troj/Salat-B |
Details From VirusTotal
Basic Properties
| MD5 | 257bf3cc6bc44505dd1f3bba6eb2e1c6 |
| SHA-1 | 85445860a44f5eec61599eb42a76350c1409e226 |
| SHA-256 | 1df2811ec4da6f69117bc675b1720cf060c809925a896b4bdc56fcb9ae2bbec8 |
| VHash | 03603e0f7d1bz4!z |
| SSDEEP | 49152:J+TZ9CEuT1oZbKR/loU0PndiSxuEhQxqenE/eCCJ/cTStu8O7YDPTqPilr17xDwp:E/9uKwL0PdiSwEm1JaP8EYD7qP2syI0 |
| TLSH | T166F533C28BC0F59AC6239EB06B871C93B6B5F8CBE45E1B7544FCA81A83C497E1985471 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| File size | 3.4 MB |
History
| First seen on VirusTotal | 2026-09-25 09:45 UTC |
| Last submission | 2026-09-25 11:53 UTC |
| Last analysis | 2026-09-25 11:53 UTC |
| Last modified on VirusTotal | 2026-09-25 13:54 UTC |
Known Names
hmr52cw8q.exe9fr18d8.exeupdater_rFxWppLs.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 3593216 bytes. Tags: exe, salat, salatstealer, stealer, upx. Reporter: Kejult. First seen: 2026-09-25 11:14:28.
Remediations (10)
-
web:any.run
SalatStealer malware, a Go-based infostealer, targets browser credentials, cryptocurrency wallets, and Telegram sessions using advanced evasion and persistence techniques.
-
web:bazaar.abuse.ch
SalatStealer malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as SalatStealer . Database Entry
-
web:boteraser.com
🛡️ Mitigation To defend against SalatStealer , organizations should block execution of unsigned binaries downloaded from the internet, enable Windows Defender real-time protection with cloud-delivered protection, and implement application control policies that prevent unauthorized scripts and executables from running.
-
web:cybersecuritynews.com
Salat Stealer targets Windows, stealing browser logins and crypto wallets via fake cracks, cheats, and stealthy Go-based evasion.
-
web:socprime.com
Salat Stealer is a Go-based remote access trojan that functions as a full-featured post-exploitation framework. It supports multiple communication channels, including WebSocket, HTTP/2, HTTP/3, and QUIC, giving operators flexible and resilient command-and-control options.
-
web:www.broadcom.com
Salat Stealer, a Go-based infostealer offered under a Malware-as-a-Service model, has been reported by Cyfirma. Likely operated by Russian-speaking actors, the malware employs layered persistence techniques, including registry Run keys, scheduled tasks, process masquerading and modifications to Windows Defender exclusions to evade detection.
-
web:www.cyfirma.com
CONCLUSION Salat Stealer exemplifies the growing sophistication of Malware-as-a-Service ecosystems, blending advanced persistence, evasion, and data theft techniques with resilient C2 operations. Its ability to harvest browser credentials, cryptocurrency assets, and session data poses significant risks to individuals and enterprises alike.
-
web:www.dexpose.io
SalatStealer is a stealthy and persistent malware designed to steal sensitive data while evading detection. By harvesting credentials, exfiltrating files, and enabling real-time surveillance, it poses severe risks to victims, including financial loss, identity theft, and privacy breaches.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.pcrisk.com
Malware removal rarely necessitates formatting. What are the biggest issues that Salat malware can cause? The dangers posed by an infection depend on the malware's abilities and the cyber criminals' modus operandi. Salat is a stealer that can download victims' files, record audio/video, live-stream desktops, and perform other malicious activities.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.