MB-e64b70bbc632b834064b4b268405323e0a83c5d63102b49c903792cb79c5a1fa
high
📛 Threat Title
SalatStealer: Rexil.exe
Description
File type: exe. Size: 3593728 bytes. Tags: exe, salat, salatstealer, upx. Reporter: Alex_sev. First seen: 2026-08-04 18:17:00.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
6ed4f5f04d62b18d96b26d6db7c18840
IOC database
- Type
- hash_imphash
- Value
6ed4f5f04d62b18d96b26d6db7c18840- First seen
- Last seen
- Attached to this threat
- Appears in
- 40 threats
- Description
- imphash of URLhaus payload f36467769f8a9e79…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
e64b70bbc632b834064b4b268405323e0a83c5d63102b49c903792cb79c5a1fa
IOC database
- Type
- hash_sha256
- Value
e64b70bbc632b834064b4b268405323e0a83c5d63102b49c903792cb79c5a1fa- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- SalatStealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
f414c3b683880f29746d821de48daf371e0a4c6e
IOC database
- Type
- hash_sha1
- Value
f414c3b683880f29746d821de48daf371e0a4c6e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
029a25a2a7fdf939b9b7e361f8fe2272
IOC database
- Type
- hash_md5
- Value
029a25a2a7fdf939b9b7e361f8fe2272- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 3593728 bytes. Tags: exe, salat, salatstealer, upx. Reporter: Alex_sev. First seen: 2026-08-04 18:17:00.
Remediations (10)
-
web:any.run
SalatStealer , also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.
-
web:blog.netmanageit.com
Salat Stealer, a sophisticated Go-based infostealer targeting Windows systems, has been identified. It exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques. The malware uses UPX packing, process masquerading, registry run keys, and scheduled tasks for persistence and evasion. Operated under a Malware-as-a-Service model ...
-
web:blog.netmanageit.com
7. Mitigation Strategies and Conclusion Effective defense against Salat Stealer requires a multi-layered approach. Enterprises should enforce application whitelisting, deploy endpoint detection and response tools capable of identifying unusual UPX unpacking behavior, and monitor registry hives and scheduled tasks for unauthorized entries.
-
web:cybersecuritynews.com
Salat Stealer targets Windows, stealing browser logins and crypto wallets via fake cracks, cheats, and stealthy Go-based evasion.
-
web:tria.ge
Check this salatstealer report malware sample 96ca51c01f9010e8819f208d5860d3ce05ba4d401f607d873b548caa1f2e6731, with a score of 10 out of 10.
-
web:tria.ge
Check this salatstealer report malware sample f55a0399b2a66cc064ed2612e4f05ed4da10a5ca126860945a9de50d7fcd0af1, with a score of 10 out of 10.
-
web:www.cyfirma.com
EXECUTIVE SUMMARY CYFIRMA has identified Salat Stealer (also known as WEB_RAT), a sophisticated Go-based infostealer targeting Windows systems. The malware exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques, including UPX packing, process masquerading, registry run keys, and scheduled tasks. Operated under a Malware ...
-
web:www.joesandbox.com
Deep Malware Analysis - Joe Sandbox Analysis Report Loading Joe Sandbox Report ... Play interactive tourEdit tour Windows Analysis Report Rexil.exe
-
web:www.pcrisk.com
Malware removal rarely necessitates formatting. What are the biggest issues that Salat malware can cause? The dangers posed by an infection depend on the malware's abilities and the cyber criminals' modus operandi. Salat is a stealer that can download victims' files, record audio/video, live-stream desktops, and perform other malicious activities.
-
web:www.securitricks.com
Salat Stealer, also known as WEB_RAT, is a sophisticated Go-based infostealer targeting Windows systems. It exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques. The malware uses UPX packing, process masquerading, registry run keys, and scheduled tasks for persistence and evasion. Operated under a Malware-as-a-Service ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.