s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932565 high

📛 Threat Title

SalatStealer: SHA256 hash of a malware sample (payload) 7c04a11b72485957f38a65a92666de7d0a6f80fee78e45638a5db5505ae318e1

Category: SalatStealer Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: SalatStealer. Confidence: 95. First seen: 2026-09-25 01:44:50 UTC. Reporter: whack_sh. Tags: exe, SalatStealer, stealer, upx.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 7c04a11b72485957f38a65a92666de7d0a6f80fee78e45638a5db5505ae318e1

IOC database

Type
hash_sha256
Value
7c04a11b72485957f38a65a92666de7d0a6f80fee78e45638a5db5505ae318e1
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
SHA256 hash of a malware sample (payload) attributed to SalatStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: SalatStealer. Confidence: 95. First seen: 2026-09-25 01:44:50 UTC. Reporter: whack_sh. Tags: exe, SalatStealer, stealer, upx.

Remediations (10)

  • web:any.run

    SalatStealer malware , a Go-based infostealer, targets browser credentials, cryptocurrency wallets, and Telegram sessions using advanced evasion and persistence techniques.

  • web:bazaar.abuse.ch

    You are currently viewing the MalwareBazaar entry for SHA256 7c04a11b72485957f38a65a92666de7d0a6f80fee78e45638a5db5505ae318e1 . While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

  • web:bazaar.abuse.ch

    Information on SalatStealer malware sample ( SHA256 e97d66dc8b585de415aab8a17d0c7a59fa7d5c98edd6709f2c456db162057655) MalwareBazaar uses YARA rules from several public ...

  • web:boteraser.com

    🔍 Detection Indicators Known file hashes for SalatStealer samples include SHA256 : e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (reported by ASEC); additional hashes are listed in the ASEC blog entry.

  • web:cipherssecurity.com

    Check MD5, SHA-1, or SHA-256 file hashes against MalwareBazaar and VirusTotal feeds. Drop a file — hashing happens in your browser, never uploaded.

  • web:cyberarmor.tech

    Overview We recently identified a malware sample distributed through a YouTube video advertising a tool to "brute-force" or recover lost Bitcoin wallets. The lure is effective: it targets users who believe they can recover cryptocurrency, prompting them to execute an unknown binary. In reality, the payload is an infostealer, not a recovery ...

  • web:ismalicious.com

    Database of known malware file hashes. MD5, SHA1, and SHA256 hashes with malware family classification. Updated daily from sandbox analysis and vendor feeds.

  • web:threatfox.abuse.ch

    SalatStealer IOC: bd283bdea40a7edcccaa1abc62a4b4c187cb5ff156e357bfcf9f7fd5f07462c4 ( sha256_hash ) You are viewing the ThreatFox database entry for sha256_hash ...

  • web:www.sonicwall.com

    This week, SonicWall Capture Labs Threat Research Team analyzed a sample of SalatStealer . This is a Golang malware capable of infiltrating a system and enumerating through browsers, files, cryptowallets and systems while embedding a complete array of monitoring tools to push and pull any data on disk.

  • web:www.splunk.com

    Obtain Capabilities: Malware : T1588.001 In another campaign observed by STRT, Salat Stealer was delivered by bundling the malicious payload with Xeno Executor, a tool used to execute custom scripts within the Roblox gaming platform. The figure below shows a screenshot of the webpage from which STRT downloaded the package containing Salat Stealer.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.