s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-e64b70bbc632b834064b4b268405323e0a83c5d63102b49c903792cb79c5a1fa high

📛 Threat Title

SalatStealer: Rexil.exe

Category: SalatStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 3593728 bytes. Tags: exe, salat, salatstealer, upx. Reporter: Alex_sev. First seen: 2026-08-04 18:17:00.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 6ed4f5f04d62b18d96b26d6db7c18840

IOC database

Type
hash_imphash
Value
6ed4f5f04d62b18d96b26d6db7c18840
First seen
Last seen
Attached to this threat
Appears in
40 threats
Description
imphash of URLhaus payload f36467769f8a9e79…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 e64b70bbc632b834064b4b268405323e0a83c5d63102b49c903792cb79c5a1fa

IOC database

Type
hash_sha256
Value
e64b70bbc632b834064b4b268405323e0a83c5d63102b49c903792cb79c5a1fa
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
SalatStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 f414c3b683880f29746d821de48daf371e0a4c6e

IOC database

Type
hash_sha1
Value
f414c3b683880f29746d821de48daf371e0a4c6e
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 029a25a2a7fdf939b9b7e361f8fe2272

IOC database

Type
hash_md5
Value
029a25a2a7fdf939b9b7e361f8fe2272
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 3593728 bytes. Tags: exe, salat, salatstealer, upx. Reporter: Alex_sev. First seen: 2026-08-04 18:17:00.

Remediations (10)

  • web:any.run

    SalatStealer , also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.

  • web:blog.netmanageit.com

    Salat Stealer, a sophisticated Go-based infostealer targeting Windows systems, has been identified. It exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques. The malware uses UPX packing, process masquerading, registry run keys, and scheduled tasks for persistence and evasion. Operated under a Malware-as-a-Service model ...

  • web:blog.netmanageit.com

    7. Mitigation Strategies and Conclusion Effective defense against Salat Stealer requires a multi-layered approach. Enterprises should enforce application whitelisting, deploy endpoint detection and response tools capable of identifying unusual UPX unpacking behavior, and monitor registry hives and scheduled tasks for unauthorized entries.

  • web:cybersecuritynews.com

    Salat Stealer targets Windows, stealing browser logins and crypto wallets via fake cracks, cheats, and stealthy Go-based evasion.

  • web:tria.ge

    Check this salatstealer report malware sample 96ca51c01f9010e8819f208d5860d3ce05ba4d401f607d873b548caa1f2e6731, with a score of 10 out of 10.

  • web:tria.ge

    Check this salatstealer report malware sample f55a0399b2a66cc064ed2612e4f05ed4da10a5ca126860945a9de50d7fcd0af1, with a score of 10 out of 10.

  • web:www.cyfirma.com

    EXECUTIVE SUMMARY CYFIRMA has identified Salat Stealer (also known as WEB_RAT), a sophisticated Go-based infostealer targeting Windows systems. The malware exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques, including UPX packing, process masquerading, registry run keys, and scheduled tasks. Operated under a Malware ...

  • web:www.joesandbox.com

    Deep Malware Analysis - Joe Sandbox Analysis Report Loading Joe Sandbox Report ... Play interactive tourEdit tour Windows Analysis Report Rexil.exe

  • web:www.pcrisk.com

    Malware removal rarely necessitates formatting. What are the biggest issues that Salat malware can cause? The dangers posed by an infection depend on the malware's abilities and the cyber criminals' modus operandi. Salat is a stealer that can download victims' files, record audio/video, live-stream desktops, and perform other malicious activities.

  • web:www.securitricks.com

    Salat Stealer, also known as WEB_RAT, is a sophisticated Go-based infostealer targeting Windows systems. It exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques. The malware uses UPX packing, process masquerading, registry run keys, and scheduled tasks for persistence and evasion. Operated under a Malware-as-a-Service ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.