TF-1932565
high
📛 Threat Title
SalatStealer: SHA256 hash of a malware sample (payload) 7c04a11b72485957f38a65a92666de7d0a6f80fee78e45638a5db5505ae318e1
Description
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: SalatStealer. Confidence: 95. First seen: 2026-09-25 01:44:50 UTC. Reporter: whack_sh. Tags: exe, SalatStealer, stealer, upx.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
7c04a11b72485957f38a65a92666de7d0a6f80fee78e45638a5db5505ae318e1
IOC database
- Type
- hash_sha256
- Value
7c04a11b72485957f38a65a92666de7d0a6f80fee78e45638a5db5505ae318e1- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- SHA256 hash of a malware sample (payload) attributed to SalatStealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: SalatStealer. Confidence: 95. First seen: 2026-09-25 01:44:50 UTC. Reporter: whack_sh. Tags: exe, SalatStealer, stealer, upx.
Remediations (10)
-
web:any.run
SalatStealer malware , a Go-based infostealer, targets browser credentials, cryptocurrency wallets, and Telegram sessions using advanced evasion and persistence techniques.
-
web:bazaar.abuse.ch
You are currently viewing the MalwareBazaar entry for SHA256 7c04a11b72485957f38a65a92666de7d0a6f80fee78e45638a5db5505ae318e1 . While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
-
web:bazaar.abuse.ch
Information on SalatStealer malware sample ( SHA256 e97d66dc8b585de415aab8a17d0c7a59fa7d5c98edd6709f2c456db162057655) MalwareBazaar uses YARA rules from several public ...
-
web:boteraser.com
🔍 Detection Indicators Known file hashes for SalatStealer samples include SHA256 : e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (reported by ASEC); additional hashes are listed in the ASEC blog entry.
-
web:cipherssecurity.com
Check MD5, SHA-1, or SHA-256 file hashes against MalwareBazaar and VirusTotal feeds. Drop a file — hashing happens in your browser, never uploaded.
-
web:cyberarmor.tech
Overview We recently identified a malware sample distributed through a YouTube video advertising a tool to "brute-force" or recover lost Bitcoin wallets. The lure is effective: it targets users who believe they can recover cryptocurrency, prompting them to execute an unknown binary. In reality, the payload is an infostealer, not a recovery ...
-
web:ismalicious.com
Database of known malware file hashes. MD5, SHA1, and SHA256 hashes with malware family classification. Updated daily from sandbox analysis and vendor feeds.
-
web:threatfox.abuse.ch
SalatStealer IOC: bd283bdea40a7edcccaa1abc62a4b4c187cb5ff156e357bfcf9f7fd5f07462c4 ( sha256_hash ) You are viewing the ThreatFox database entry for sha256_hash ...
-
web:www.sonicwall.com
This week, SonicWall Capture Labs Threat Research Team analyzed a sample of SalatStealer . This is a Golang malware capable of infiltrating a system and enumerating through browsers, files, cryptowallets and systems while embedding a complete array of monitoring tools to push and pull any data on disk.
-
web:www.splunk.com
Obtain Capabilities: Malware : T1588.001 In another campaign observed by STRT, Salat Stealer was delivered by bundling the malicious payload with Xeno Executor, a tool used to execute custom scripts within the Roblox gaming platform. The figure below shows a screenshot of the webpage from which STRT downloaded the package containing Salat Stealer.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.