MB-0e5159f1b507b56a59adc39564646aa07f83f1fced3dad6872e3752d777ea885
high
📛 Threat Title
SalatStealer: Rexil.exe
Description
File type: exe. Size: 12571648 bytes. Tags: exe, SalatStealer, upx-dec. Reporter: abuse_ch. First seen: 2026-08-04 18:17:40.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
1aae8bf580c846f39c71c05898e57e88
IOC database
- Type
- hash_imphash
- Value
1aae8bf580c846f39c71c05898e57e88- First seen
- Last seen
- Attached to this threat
- Appears in
- 59 threats
- Description
- imphash of URLhaus payload d06c8ee46e760f39…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
0e5159f1b507b56a59adc39564646aa07f83f1fced3dad6872e3752d777ea885
IOC database
- Type
- hash_sha256
- Value
0e5159f1b507b56a59adc39564646aa07f83f1fced3dad6872e3752d777ea885- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- SalatStealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
abab65688d031dc52f69549b2436a85a76618cd3
IOC database
- Type
- hash_sha1
- Value
abab65688d031dc52f69549b2436a85a76618cd3- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
ada2c8fc6d7aa2abeb90c768f6ab97fb
IOC database
- Type
- hash_md5
- Value
ada2c8fc6d7aa2abeb90c768f6ab97fb- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 12571648 bytes. Tags: exe, SalatStealer, upx-dec. Reporter: abuse_ch. First seen: 2026-08-04 18:17:40.
Remediations (10)
-
web:any.run
SalatStealer , also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.
-
web:any.run
MALICIOUS SALATSTEALER mutex has been found dasHost.exe (PID: 7408) 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940) dllhost.exe (PID: 7708) dasHost.exe (PID: 2144) StartMenuExperienceHost.exe (PID: 8040) Steals credentials from Web Browsers dasHost.exe (PID: 7408) Actions looks like stealing of personal data dasHost.exe (PID: 7408) Starts REAGENTC.EXE to disable the Windows Recovery ...
-
web:blog.jrdioca.com
Reverse Engineering, Malware Analysis · 25 Jul 2025 Salat Stealer Summary This report analyzes a UPX-packed Windows executable file identified as a Salat Stealer. The malware collects the victim's keystrokes, system information, browser-stored credentials, cryptocurrency wallet data, and messaging applications data. It can also access the victim's webcam and microphone. It compresses the ...
-
web:blog.netmanageit.com
7. Mitigation Strategies and Conclusion Effective defense against Salat Stealer requires a multi-layered approach. Enterprises should enforce application whitelisting, deploy endpoint detection and response tools capable of identifying unusual UPX unpacking behavior, and monitor registry hives and scheduled tasks for unauthorized entries.
-
web:tria.ge
Check this salatstealer report malware sample f55a0399b2a66cc064ed2612e4f05ed4da10a5ca126860945a9de50d7fcd0af1, with a score of 10 out of 10.
-
web:tria.ge
Check this salatstealer report malware sample b18125c86af11e1b717036a3e2907d0f0b7d6a32f9cb7fd34a97396f27a6a5fb, with a score of 10 out of 10.
-
web:www.cyfirma.com
EXECUTIVE SUMMARY CYFIRMA has identified Salat Stealer (also known as WEB_RAT), a sophisticated Go-based infostealer targeting Windows systems. The malware exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques, including UPX packing, process masquerading, registry run keys, and scheduled tasks. Operated under a Malware ...
-
web:www.joesandbox.com
Automated Malware Analysis - Joe Sandbox Management Report Compliance Uses 32bit PE files Source: Rexil.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE Uses secure TLS version for HTTPS connections Source: unknown HTTPS traffic detected: 172.65.251.78:443 -> 192.168.2.4:49785 version: TLS 1.2 Contains modern PE file flags such as dynamic base (ASLR) or NX Source: Rexil.exe Static PE ...
-
web:www.pcrisk.com
What kind of malware is Salat? Salat (also known as WEB_RAT) is a malicious program written in the Go programming language. This malware is designed to steal sensitive information from infected devices, and due to this behavior - it is classified as a stealer. Salat malware overview Salat is a stealer-type malware, and upon successful infiltration, it starts collecting relevant device data ...
-
web:www.securitricks.com
Salat Stealer, also known as WEB_RAT, is a sophisticated Go-based infostealer targeting Windows systems. It exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques. The malware uses UPX packing, process masquerading, registry run keys, and scheduled tasks for persistence and evasion. Operated under a Malware-as-a-Service ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.