s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-0e5159f1b507b56a59adc39564646aa07f83f1fced3dad6872e3752d777ea885 high

📛 Threat Title

SalatStealer: Rexil.exe

Category: SalatStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 12571648 bytes. Tags: exe, SalatStealer, upx-dec. Reporter: abuse_ch. First seen: 2026-08-04 18:17:40.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 1aae8bf580c846f39c71c05898e57e88

IOC database

Type
hash_imphash
Value
1aae8bf580c846f39c71c05898e57e88
First seen
Last seen
Attached to this threat
Appears in
59 threats
Description
imphash of URLhaus payload d06c8ee46e760f39…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 0e5159f1b507b56a59adc39564646aa07f83f1fced3dad6872e3752d777ea885

IOC database

Type
hash_sha256
Value
0e5159f1b507b56a59adc39564646aa07f83f1fced3dad6872e3752d777ea885
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
SalatStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 abab65688d031dc52f69549b2436a85a76618cd3

IOC database

Type
hash_sha1
Value
abab65688d031dc52f69549b2436a85a76618cd3
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 ada2c8fc6d7aa2abeb90c768f6ab97fb

IOC database

Type
hash_md5
Value
ada2c8fc6d7aa2abeb90c768f6ab97fb
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 12571648 bytes. Tags: exe, SalatStealer, upx-dec. Reporter: abuse_ch. First seen: 2026-08-04 18:17:40.

Remediations (10)

  • web:any.run

    SalatStealer , also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.

  • web:any.run

    MALICIOUS SALATSTEALER mutex has been found dasHost.exe (PID: 7408) 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940) dllhost.exe (PID: 7708) dasHost.exe (PID: 2144) StartMenuExperienceHost.exe (PID: 8040) Steals credentials from Web Browsers dasHost.exe (PID: 7408) Actions looks like stealing of personal data dasHost.exe (PID: 7408) Starts REAGENTC.EXE to disable the Windows Recovery ...

  • web:blog.jrdioca.com

    Reverse Engineering, Malware Analysis · 25 Jul 2025 Salat Stealer Summary This report analyzes a UPX-packed Windows executable file identified as a Salat Stealer. The malware collects the victim's keystrokes, system information, browser-stored credentials, cryptocurrency wallet data, and messaging applications data. It can also access the victim's webcam and microphone. It compresses the ...

  • web:blog.netmanageit.com

    7. Mitigation Strategies and Conclusion Effective defense against Salat Stealer requires a multi-layered approach. Enterprises should enforce application whitelisting, deploy endpoint detection and response tools capable of identifying unusual UPX unpacking behavior, and monitor registry hives and scheduled tasks for unauthorized entries.

  • web:tria.ge

    Check this salatstealer report malware sample f55a0399b2a66cc064ed2612e4f05ed4da10a5ca126860945a9de50d7fcd0af1, with a score of 10 out of 10.

  • web:tria.ge

    Check this salatstealer report malware sample b18125c86af11e1b717036a3e2907d0f0b7d6a32f9cb7fd34a97396f27a6a5fb, with a score of 10 out of 10.

  • web:www.cyfirma.com

    EXECUTIVE SUMMARY CYFIRMA has identified Salat Stealer (also known as WEB_RAT), a sophisticated Go-based infostealer targeting Windows systems. The malware exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques, including UPX packing, process masquerading, registry run keys, and scheduled tasks. Operated under a Malware ...

  • web:www.joesandbox.com

    Automated Malware Analysis - Joe Sandbox Management Report Compliance Uses 32bit PE files Source: Rexil.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE Uses secure TLS version for HTTPS connections Source: unknown HTTPS traffic detected: 172.65.251.78:443 -> 192.168.2.4:49785 version: TLS 1.2 Contains modern PE file flags such as dynamic base (ASLR) or NX Source: Rexil.exe Static PE ...

  • web:www.pcrisk.com

    What kind of malware is Salat? Salat (also known as WEB_RAT) is a malicious program written in the Go programming language. This malware is designed to steal sensitive information from infected devices, and due to this behavior - it is classified as a stealer. Salat malware overview Salat is a stealer-type malware, and upon successful infiltration, it starts collecting relevant device data ...

  • web:www.securitricks.com

    Salat Stealer, also known as WEB_RAT, is a sophisticated Go-based infostealer targeting Windows systems. It exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques. The malware uses UPX packing, process masquerading, registry run keys, and scheduled tasks for persistence and evasion. Operated under a Malware-as-a-Service ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.