s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-b2a7b0c07e3a902568c0688376632221f696dfad34de120a821c4d4b7666aa88 high

📛 Threat Title

SalatStealer: 5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7.exe

Category: SalatStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 12572160 bytes. Tags: exe, salat, salatstealer, stealer. Reporter: Kejult. First seen: 2026-09-25 11:11:48.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 1aae8bf580c846f39c71c05898e57e88

IOC database

Type
hash_imphash
Value
1aae8bf580c846f39c71c05898e57e88
First seen
Last seen
Attached to this threat
Appears in
100 threats
Description
imphash of URLhaus payload d06c8ee46e760f39…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 b2a7b0c07e3a902568c0688376632221f696dfad34de120a821c4d4b7666aa88 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/b2a7b0c07e3a902568c0688376632221f696dfad34de120a821c4d4b7666aa88

IOC database

Type
hash_sha256
Value
b2a7b0c07e3a902568c0688376632221f696dfad34de120a821c4d4b7666aa88
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
SalatStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/b2a7b0c07e3a902568c0688376632221f696dfad34de120a821c4d4b7666aa88

hash_sha1 776537e4e3dc06deab403aea7e6f61984fec920d VT 44 / 75

IOC database

Type
hash_sha1
Value
776537e4e3dc06deab403aea7e6f61984fec920d
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 44 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R727379
ALYac malicious Trojan.LummaStealer.103
Arcabit malicious Trojan.LummaStealer.103
Avast malicious Win32:SalatStealer-A [Pws]
AVG malicious Win32:SalatStealer-A [Pws]
Avira malicious TR/W32.Evo
BitDefender malicious Trojan.LummaStealer.103
Bkav malicious W32.Malware.6AEC00BF
ClamAV malicious Win.Malware.Salat-10058846-0
CrowdStrike malicious win/malicious_confidence_100% (D)
CTX malicious exe.trojan.lummastealer
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Salat.389
Elastic malicious Multi.Generic.Threat
Emsisoft malicious Trojan.LummaStealer.103 (B)
ESET-NOD32 malicious WinGo/Agent.VO trojan
F-Secure malicious Trojan.TR/W32.Evo
Fortinet malicious W32/Agent.VO!tr
GData malicious Trojan.LummaStealer.103
Google malicious Detected
huorong malicious Trojan/Agent.e!crit
Ikarus malicious Trojan.Win32.SalatStealer
K7AntiVirus malicious Spyware ( 006d58511 )
K7GW malicious Spyware ( 006d58511 )
Kaspersky malicious HEUR:Trojan-PSW.Win32.Convagent.gen
Malwarebytes malicious Spyware.SalatStealer
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious Trojan:Win/SalatStealer.AA
Microsoft malicious Trojan:Win32/SalatStealer!pz
MicroWorld-eScan malicious Trojan.LummaStealer.103
Rising malicious Stealer.Salat!1.13A22 (CLASSIC)
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious SalatStealer!73A1DCF2E01F
Sophos malicious Troj/Salat-A
Symantec malicious ML.Attribute.HighConfidence
TACHYON malicious Banker/W32.Agent.12572160.L
Tencent malicious Trojan.Win32.Stealer.16001830
TrellixENS malicious SalatStealer!73A1DCF2E01F
TrendMicro-HouseCall malicious Trojan.Win32.VSX.PE04CAF
Varist malicious W32/Salat.A.gen!Eldorado
VIPRE malicious Trojan.LummaStealer.103
VirIT malicious Trojan.Win32.SalatStlr.JYC
ZoneAlarm malicious Troj/Salat-A

Details From VirusTotal

Basic Properties
MD573a1dcf2e01fae18c38749b92509ee27
SHA-1776537e4e3dc06deab403aea7e6f61984fec920d
SHA-256b2a7b0c07e3a902568c0688376632221f696dfad34de120a821c4d4b7666aa88
VHash017066656d5d15641az2c!z
SSDEEP98304:yun+uBu7zmCvjkqwntcKNiAr4tG20CzEc0:2uK/jl4cK80Ht1
TLSHT11BC65B11FADB95F2E9035831016BB37F23315D048B28CB9BEB547B2AF87B6A11D66305
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows
File size12.0 MB
History
First seen on VirusTotal2026-09-25 10:50 UTC
Last submission2026-09-25 10:50 UTC
Last analysis2026-09-25 10:50 UTC
Last modified on VirusTotal2026-09-25 23:23 UTC
Known Names
  • owhst7.exe
  • 5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7.exe
hash_md5 73a1dcf2e01fae18c38749b92509ee27 VT 44 / 75

IOC database

Type
hash_md5
Value
73a1dcf2e01fae18c38749b92509ee27
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 44 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R727379
ALYac malicious Trojan.LummaStealer.103
Arcabit malicious Trojan.LummaStealer.103
Avast malicious Win32:SalatStealer-A [Pws]
AVG malicious Win32:SalatStealer-A [Pws]
Avira malicious TR/W32.Evo
BitDefender malicious Trojan.LummaStealer.103
Bkav malicious W32.Malware.6AEC00BF
ClamAV malicious Win.Malware.Salat-10058846-0
CrowdStrike malicious win/malicious_confidence_100% (D)
CTX malicious exe.trojan.lummastealer
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Salat.389
Elastic malicious Multi.Generic.Threat
Emsisoft malicious Trojan.LummaStealer.103 (B)
ESET-NOD32 malicious WinGo/Agent.VO trojan
F-Secure malicious Trojan.TR/W32.Evo
Fortinet malicious W32/Agent.VO!tr
GData malicious Trojan.LummaStealer.103
Google malicious Detected
huorong malicious Trojan/Agent.e!crit
Ikarus malicious Trojan.Win32.SalatStealer
K7AntiVirus malicious Spyware ( 006d58511 )
K7GW malicious Spyware ( 006d58511 )
Kaspersky malicious HEUR:Trojan-PSW.Win32.Convagent.gen
Malwarebytes malicious Spyware.SalatStealer
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious Trojan:Win/SalatStealer.AA
Microsoft malicious Trojan:Win32/SalatStealer!pz
MicroWorld-eScan malicious Trojan.LummaStealer.103
Rising malicious Stealer.Salat!1.13A22 (CLASSIC)
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious SalatStealer!73A1DCF2E01F
Sophos malicious Troj/Salat-A
Symantec malicious ML.Attribute.HighConfidence
TACHYON malicious Banker/W32.Agent.12572160.L
Tencent malicious Trojan.Win32.Stealer.16001830
TrellixENS malicious SalatStealer!73A1DCF2E01F
TrendMicro-HouseCall malicious Trojan.Win32.VSX.PE04CAF
Varist malicious W32/Salat.A.gen!Eldorado
VIPRE malicious Trojan.LummaStealer.103
VirIT malicious Trojan.Win32.SalatStlr.JYC
ZoneAlarm malicious Troj/Salat-A

Details From VirusTotal

Basic Properties
MD573a1dcf2e01fae18c38749b92509ee27
SHA-1776537e4e3dc06deab403aea7e6f61984fec920d
SHA-256b2a7b0c07e3a902568c0688376632221f696dfad34de120a821c4d4b7666aa88
VHash017066656d5d15641az2c!z
SSDEEP98304:yun+uBu7zmCvjkqwntcKNiAr4tG20CzEc0:2uK/jl4cK80Ht1
TLSHT11BC65B11FADB95F2E9035831016BB37F23315D048B28CB9BEB547B2AF87B6A11D66305
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows
File size12.0 MB
History
First seen on VirusTotal2026-09-25 10:50 UTC
Last submission2026-09-25 10:50 UTC
Last analysis2026-09-25 10:50 UTC
Last modified on VirusTotal2026-09-25 23:23 UTC
Known Names
  • owhst7.exe
  • 5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 12572160 bytes. Tags: exe, salat, salatstealer, stealer. Reporter: Kejult. First seen: 2026-09-25 11:11:48.

Remediations (10)

  • web:any.run

    SalatStealer malware, a Go-based infostealer, targets browser credentials, cryptocurrency wallets, and Telegram sessions using advanced evasion and persistence techniques.

  • web:bazaar.abuse.ch

    SalatStealer malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as SalatStealer . Database Entry

  • web:boteraser.com

    🛡️ Mitigation To defend against SalatStealer , organizations should block execution of unsigned binaries downloaded from the internet, enable Windows Defender real-time protection with cloud-delivered protection, and implement application control policies that prevent unauthorized scripts and executables from running.

  • web:cybersecuritynews.com

    Salat Stealer targets Windows, stealing browser logins and crypto wallets via fake cracks, cheats, and stealthy Go-based evasion.

  • web:socprime.com

    Salat Stealer is a Go-based remote access trojan that functions as a full-featured post-exploitation framework. It supports multiple communication channels, including WebSocket, HTTP/2, HTTP/3, and QUIC, giving operators flexible and resilient command-and-control options.

  • web:www.broadcom.com

    Salat Stealer, a Go-based infostealer offered under a Malware-as-a-Service model, has been reported by Cyfirma. Likely operated by Russian-speaking actors, the malware employs layered persistence techniques, including registry Run keys, scheduled tasks, process masquerading and modifications to Windows Defender exclusions to evade detection.

  • web:www.cyfirma.com

    CONCLUSION Salat Stealer exemplifies the growing sophistication of Malware-as-a-Service ecosystems, blending advanced persistence, evasion, and data theft techniques with resilient C2 operations. Its ability to harvest browser credentials, cryptocurrency assets, and session data poses significant risks to individuals and enterprises alike.

  • web:www.dexpose.io

    SalatStealer is a stealthy and persistent malware designed to steal sensitive data while evading detection. By harvesting credentials, exfiltrating files, and enabling real-time surveillance, it poses severe risks to victims, including financial loss, identity theft, and privacy breaches.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.pcrisk.com

    Malware removal rarely necessitates formatting. What are the biggest issues that Salat malware can cause? The dangers posed by an infection depend on the malware's abilities and the cyber criminals' modus operandi. Salat is a stealer that can download victims' files, record audio/video, live-stream desktops, and perform other malicious activities.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.