MB-5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7
high
📛 Threat Title
SalatStealer: 5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7.exe
Description
File type: exe. Size: 3594752 bytes. Tags: exe, salat, salatstealer, stealer, upx. Reporter: Kejult. First seen: 2026-09-25 11:16:03.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
6ed4f5f04d62b18d96b26d6db7c18840
IOC database
- Type
- hash_imphash
- Value
6ed4f5f04d62b18d96b26d6db7c18840- First seen
- Last seen
- Attached to this threat
- Appears in
- 87 threats
- Description
- imphash of URLhaus payload f36467769f8a9e79…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7
VT 42 / 75
IOC database
- Type
- hash_sha256
- Value
5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- SalatStealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 42 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.R757154 |
| ALYac | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| APEX | malicious | Malicious |
| Arcabit | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| Avast | malicious | Win32:Evo-gen [Trj] |
| AVG | malicious | Win32:Evo-gen [Trj] |
| Avira | malicious | TR/W32.Evo |
| BitDefender | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| Bkav | malicious | W32.Malware.239DA8F3 |
| CrowdStrike | malicious | win/malicious_confidence_100% (D) |
| CTX | malicious | exe.unknown.dacic |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 100) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Salat.389 |
| Elastic | malicious | malicious (moderate confidence) |
| Emsisoft | malicious | Dump:Generic.Dacic.18086.CB77C457 (B) |
| ESET-NOD32 | malicious | WinGo/Agent.AXZ trojan |
| F-Secure | malicious | Trojan.TR/W32.Evo |
| Fortinet | malicious | W32/Agent.XS!tr |
| GData | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Agent.e!crit |
| Ikarus | malicious | Trojan.Win32.SalatStealer |
| K7AntiVirus | malicious | Trojan ( 005ce1d91 ) |
| K7GW | malicious | Trojan ( 005ce1d91 ) |
| Malwarebytes | malicious | Trojan.MalPack.Generic |
| MaxSecure | malicious | Trojan.Malware.300983.susgen |
| McAfeeD | malicious | Real Protect-LS!C17E0FF66C5F |
| Microsoft | malicious | Trojan:Win32/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| Rising | malicious | Stealer.Salat!1.13A22 (CLASSIC) |
| SentinelOne | malicious | Static AI - Malicious PE |
| Sophos | malicious | Troj/Salat-B |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TACHYON | malicious | Banker/W32.Agent.12572160.L |
| Tencent | malicious | Trojan.Win32.Stealer.16001830 |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | GenericRXWV-UH!BF087AA74F91 |
| VIPRE | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| Webroot | malicious | W32.Malware.gen |
| ZoneAlarm | malicious | Troj/Salat-B |
Details From VirusTotal
Basic Properties
| MD5 | c17e0ff66c5f4934c655c46d2a75ebf5 |
| SHA-1 | a0c705bdf32d4443952db287d5534725aa8a67d2 |
| SHA-256 | 5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7 |
| VHash | 03603e0f7d1bz4!z |
| SSDEEP | 98304:vo/EPGgRFBsxu7gEpf9Wwz179lr0Nnm+bh5sbUxB:5PGy7n1Jz1Itbh2b6B |
| TLSH | T169F5333A875CD682EB855CB4F7E61A474317530862E27371227CBFC54817EA8D7388BA |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| File size | 3.4 MB |
History
| First seen on VirusTotal | 2026-09-25 09:50 UTC |
| Last submission | 2026-09-25 09:50 UTC |
| Last analysis | 2026-09-25 09:50 UTC |
| Last modified on VirusTotal | 2026-09-25 15:26 UTC |
Known Names
drlz73.exeupdater_XmGSZYjT.exe
hash_sha1
a0c705bdf32d4443952db287d5534725aa8a67d2
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/a0c705bdf32d4443952db287d5534725aa8a67d2
IOC database
- Type
- hash_sha1
- Value
a0c705bdf32d4443952db287d5534725aa8a67d2- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/a0c705bdf32d4443952db287d5534725aa8a67d2
hash_md5
c17e0ff66c5f4934c655c46d2a75ebf5
VT 42 / 75
IOC database
- Type
- hash_md5
- Value
c17e0ff66c5f4934c655c46d2a75ebf5- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 42 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.R757154 |
| ALYac | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| APEX | malicious | Malicious |
| Arcabit | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| Avast | malicious | Win32:Evo-gen [Trj] |
| AVG | malicious | Win32:Evo-gen [Trj] |
| Avira | malicious | TR/W32.Evo |
| BitDefender | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| Bkav | malicious | W32.Malware.239DA8F3 |
| CrowdStrike | malicious | win/malicious_confidence_100% (D) |
| CTX | malicious | exe.unknown.dacic |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 100) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Salat.389 |
| Elastic | malicious | malicious (moderate confidence) |
| Emsisoft | malicious | Dump:Generic.Dacic.18086.CB77C457 (B) |
| ESET-NOD32 | malicious | WinGo/Agent.AXZ trojan |
| F-Secure | malicious | Trojan.TR/W32.Evo |
| Fortinet | malicious | W32/Agent.XS!tr |
| GData | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Agent.e!crit |
| Ikarus | malicious | Trojan.Win32.SalatStealer |
| K7AntiVirus | malicious | Trojan ( 005ce1d91 ) |
| K7GW | malicious | Trojan ( 005ce1d91 ) |
| Malwarebytes | malicious | Trojan.MalPack.Generic |
| MaxSecure | malicious | Trojan.Malware.300983.susgen |
| McAfeeD | malicious | Real Protect-LS!C17E0FF66C5F |
| Microsoft | malicious | Trojan:Win32/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| Rising | malicious | Stealer.Salat!1.13A22 (CLASSIC) |
| SentinelOne | malicious | Static AI - Malicious PE |
| Sophos | malicious | Troj/Salat-B |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TACHYON | malicious | Banker/W32.Agent.12572160.L |
| Tencent | malicious | Trojan.Win32.Stealer.16001830 |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | GenericRXWV-UH!BF087AA74F91 |
| VIPRE | malicious | Dump:Generic.Dacic.18086.CB77C457 |
| Webroot | malicious | W32.Malware.gen |
| ZoneAlarm | malicious | Troj/Salat-B |
Details From VirusTotal
Basic Properties
| MD5 | c17e0ff66c5f4934c655c46d2a75ebf5 |
| SHA-1 | a0c705bdf32d4443952db287d5534725aa8a67d2 |
| SHA-256 | 5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7 |
| VHash | 03603e0f7d1bz4!z |
| SSDEEP | 98304:vo/EPGgRFBsxu7gEpf9Wwz179lr0Nnm+bh5sbUxB:5PGy7n1Jz1Itbh2b6B |
| TLSH | T169F5333A875CD682EB855CB4F7E61A474317530862E27371227CBFC54817EA8D7388BA |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| File size | 3.4 MB |
History
| First seen on VirusTotal | 2026-09-25 09:50 UTC |
| Last submission | 2026-09-25 09:50 UTC |
| Last analysis | 2026-09-25 09:50 UTC |
| Last modified on VirusTotal | 2026-09-25 15:26 UTC |
Known Names
drlz73.exeupdater_XmGSZYjT.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 3594752 bytes. Tags: exe, salat, salatstealer, stealer, upx. Reporter: Kejult. First seen: 2026-09-25 11:16:03.
Remediations (10)
-
web:any.run
SalatStealer malware, a Go-based infostealer, targets browser credentials, cryptocurrency wallets, and Telegram sessions using advanced evasion and persistence techniques.
-
web:bazaar.abuse.ch
SalatStealer malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as SalatStealer . Database Entry
-
web:bazaar.abuse.ch
Information on SalatStealer malware sample (SHA256 33b0051d927f628af7293011b29e7db3a600bf1d67e605bcf523712b4a04e0e9) YARA Signatures MalwareBazaar uses YARA rules ...
-
web:boteraser.com
🛡️ Mitigation To defend against SalatStealer , organizations should block execution of unsigned binaries downloaded from the internet, enable Windows Defender real-time protection with cloud-delivered protection, and implement application control policies that prevent unauthorized scripts and executables from running.
-
web:cybersecuritynews.com
Salat Stealer targets Windows, stealing browser logins and crypto wallets via fake cracks, cheats, and stealthy Go-based evasion.
-
web:darkatlas.io
Technical analysis of Salat Stealer, a Go-based RAT with resilient C2, credential theft, persistence, and remote control features.
-
web:www.cyfirma.com
CONCLUSION Salat Stealer exemplifies the growing sophistication of Malware-as-a-Service ecosystems, blending advanced persistence, evasion, and data theft techniques with resilient C2 operations. Its ability to harvest browser credentials, cryptocurrency assets, and session data poses significant risks to individuals and enterprises alike.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.pcrisk.com
What kind of malware is Salat? Salat (also known as WEB_RAT) is a malicious program written in the Go programming language. This malware is designed to steal sensitive information from infected devices, and due to this behavior - it is classified as a stealer. Salat malware overview Salat is a stealer-type malware, and upon successful infiltration, it starts collecting relevant device data ...
-
web:www.splunk.com
Learn how the Salat Stealer campaign uses Go-based surveillance and data exfiltration, and explore its infection chain and how to hunt for this threat using Splunk.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.