s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7 high

📛 Threat Title

SalatStealer: 5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7.exe

Category: SalatStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 3594752 bytes. Tags: exe, salat, salatstealer, stealer, upx. Reporter: Kejult. First seen: 2026-09-25 11:16:03.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 6ed4f5f04d62b18d96b26d6db7c18840

IOC database

Type
hash_imphash
Value
6ed4f5f04d62b18d96b26d6db7c18840
First seen
Last seen
Attached to this threat
Appears in
87 threats
Description
imphash of URLhaus payload f36467769f8a9e79…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7 VT 42 / 75

IOC database

Type
hash_sha256
Value
5169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
SalatStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 42 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R757154
ALYac malicious Dump:Generic.Dacic.18086.CB77C457
APEX malicious Malicious
Arcabit malicious Dump:Generic.Dacic.18086.CB77C457
Avast malicious Win32:Evo-gen [Trj]
AVG malicious Win32:Evo-gen [Trj]
Avira malicious TR/W32.Evo
BitDefender malicious Dump:Generic.Dacic.18086.CB77C457
Bkav malicious W32.Malware.239DA8F3
CrowdStrike malicious win/malicious_confidence_100% (D)
CTX malicious exe.unknown.dacic
Cylance malicious Unsafe
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Salat.389
Elastic malicious malicious (moderate confidence)
Emsisoft malicious Dump:Generic.Dacic.18086.CB77C457 (B)
ESET-NOD32 malicious WinGo/Agent.AXZ trojan
F-Secure malicious Trojan.TR/W32.Evo
Fortinet malicious W32/Agent.XS!tr
GData malicious Dump:Generic.Dacic.18086.CB77C457
Google malicious Detected
huorong malicious Trojan/Agent.e!crit
Ikarus malicious Trojan.Win32.SalatStealer
K7AntiVirus malicious Trojan ( 005ce1d91 )
K7GW malicious Trojan ( 005ce1d91 )
Malwarebytes malicious Trojan.MalPack.Generic
MaxSecure malicious Trojan.Malware.300983.susgen
McAfeeD malicious Real Protect-LS!C17E0FF66C5F
Microsoft malicious Trojan:Win32/Wacatac.B!ml
MicroWorld-eScan malicious Dump:Generic.Dacic.18086.CB77C457
Rising malicious Stealer.Salat!1.13A22 (CLASSIC)
SentinelOne malicious Static AI - Malicious PE
Sophos malicious Troj/Salat-B
Symantec malicious ML.Attribute.HighConfidence
TACHYON malicious Banker/W32.Agent.12572160.L
Tencent malicious Trojan.Win32.Stealer.16001830
Trapmine malicious malicious.high.ml.score
TrellixENS malicious GenericRXWV-UH!BF087AA74F91
VIPRE malicious Dump:Generic.Dacic.18086.CB77C457
Webroot malicious W32.Malware.gen
ZoneAlarm malicious Troj/Salat-B

Details From VirusTotal

Basic Properties
MD5c17e0ff66c5f4934c655c46d2a75ebf5
SHA-1a0c705bdf32d4443952db287d5534725aa8a67d2
SHA-2565169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7
VHash03603e0f7d1bz4!z
SSDEEP98304:vo/EPGgRFBsxu7gEpf9Wwz179lr0Nnm+bh5sbUxB:5PGy7n1Jz1Itbh2b6B
TLSHT169F5333A875CD682EB855CB4F7E61A474317530862E27371227CBFC54817EA8D7388BA
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
File size3.4 MB
History
First seen on VirusTotal2026-09-25 09:50 UTC
Last submission2026-09-25 09:50 UTC
Last analysis2026-09-25 09:50 UTC
Last modified on VirusTotal2026-09-25 15:26 UTC
Known Names
  • drlz73.exe
  • updater_XmGSZYjT.exe
hash_sha1 a0c705bdf32d4443952db287d5534725aa8a67d2 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/a0c705bdf32d4443952db287d5534725aa8a67d2

IOC database

Type
hash_sha1
Value
a0c705bdf32d4443952db287d5534725aa8a67d2
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/a0c705bdf32d4443952db287d5534725aa8a67d2

hash_md5 c17e0ff66c5f4934c655c46d2a75ebf5 VT 42 / 75

IOC database

Type
hash_md5
Value
c17e0ff66c5f4934c655c46d2a75ebf5
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 42 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R757154
ALYac malicious Dump:Generic.Dacic.18086.CB77C457
APEX malicious Malicious
Arcabit malicious Dump:Generic.Dacic.18086.CB77C457
Avast malicious Win32:Evo-gen [Trj]
AVG malicious Win32:Evo-gen [Trj]
Avira malicious TR/W32.Evo
BitDefender malicious Dump:Generic.Dacic.18086.CB77C457
Bkav malicious W32.Malware.239DA8F3
CrowdStrike malicious win/malicious_confidence_100% (D)
CTX malicious exe.unknown.dacic
Cylance malicious Unsafe
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Salat.389
Elastic malicious malicious (moderate confidence)
Emsisoft malicious Dump:Generic.Dacic.18086.CB77C457 (B)
ESET-NOD32 malicious WinGo/Agent.AXZ trojan
F-Secure malicious Trojan.TR/W32.Evo
Fortinet malicious W32/Agent.XS!tr
GData malicious Dump:Generic.Dacic.18086.CB77C457
Google malicious Detected
huorong malicious Trojan/Agent.e!crit
Ikarus malicious Trojan.Win32.SalatStealer
K7AntiVirus malicious Trojan ( 005ce1d91 )
K7GW malicious Trojan ( 005ce1d91 )
Malwarebytes malicious Trojan.MalPack.Generic
MaxSecure malicious Trojan.Malware.300983.susgen
McAfeeD malicious Real Protect-LS!C17E0FF66C5F
Microsoft malicious Trojan:Win32/Wacatac.B!ml
MicroWorld-eScan malicious Dump:Generic.Dacic.18086.CB77C457
Rising malicious Stealer.Salat!1.13A22 (CLASSIC)
SentinelOne malicious Static AI - Malicious PE
Sophos malicious Troj/Salat-B
Symantec malicious ML.Attribute.HighConfidence
TACHYON malicious Banker/W32.Agent.12572160.L
Tencent malicious Trojan.Win32.Stealer.16001830
Trapmine malicious malicious.high.ml.score
TrellixENS malicious GenericRXWV-UH!BF087AA74F91
VIPRE malicious Dump:Generic.Dacic.18086.CB77C457
Webroot malicious W32.Malware.gen
ZoneAlarm malicious Troj/Salat-B

Details From VirusTotal

Basic Properties
MD5c17e0ff66c5f4934c655c46d2a75ebf5
SHA-1a0c705bdf32d4443952db287d5534725aa8a67d2
SHA-2565169d3ed9f741f1fb2022a81ae25abd1bb6cfb78c7768c2c7def8a0125abb7c7
VHash03603e0f7d1bz4!z
SSDEEP98304:vo/EPGgRFBsxu7gEpf9Wwz179lr0Nnm+bh5sbUxB:5PGy7n1Jz1Itbh2b6B
TLSHT169F5333A875CD682EB855CB4F7E61A474317530862E27371227CBFC54817EA8D7388BA
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
File size3.4 MB
History
First seen on VirusTotal2026-09-25 09:50 UTC
Last submission2026-09-25 09:50 UTC
Last analysis2026-09-25 09:50 UTC
Last modified on VirusTotal2026-09-25 15:26 UTC
Known Names
  • drlz73.exe
  • updater_XmGSZYjT.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 3594752 bytes. Tags: exe, salat, salatstealer, stealer, upx. Reporter: Kejult. First seen: 2026-09-25 11:16:03.

Remediations (10)

  • web:any.run

    SalatStealer malware, a Go-based infostealer, targets browser credentials, cryptocurrency wallets, and Telegram sessions using advanced evasion and persistence techniques.

  • web:bazaar.abuse.ch

    SalatStealer malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as SalatStealer . Database Entry

  • web:bazaar.abuse.ch

    Information on SalatStealer malware sample (SHA256 33b0051d927f628af7293011b29e7db3a600bf1d67e605bcf523712b4a04e0e9) YARA Signatures MalwareBazaar uses YARA rules ...

  • web:boteraser.com

    🛡️ Mitigation To defend against SalatStealer , organizations should block execution of unsigned binaries downloaded from the internet, enable Windows Defender real-time protection with cloud-delivered protection, and implement application control policies that prevent unauthorized scripts and executables from running.

  • web:cybersecuritynews.com

    Salat Stealer targets Windows, stealing browser logins and crypto wallets via fake cracks, cheats, and stealthy Go-based evasion.

  • web:darkatlas.io

    Technical analysis of Salat Stealer, a Go-based RAT with resilient C2, credential theft, persistence, and remote control features.

  • web:www.cyfirma.com

    CONCLUSION Salat Stealer exemplifies the growing sophistication of Malware-as-a-Service ecosystems, blending advanced persistence, evasion, and data theft techniques with resilient C2 operations. Its ability to harvest browser credentials, cryptocurrency assets, and session data poses significant risks to individuals and enterprises alike.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.pcrisk.com

    What kind of malware is Salat? Salat (also known as WEB_RAT) is a malicious program written in the Go programming language. This malware is designed to steal sensitive information from infected devices, and due to this behavior - it is classified as a stealer. Salat malware overview Salat is a stealer-type malware, and upon successful infiltration, it starts collecting relevant device data ...

  • web:www.splunk.com

    Learn how the Salat Stealer campaign uses Go-based surveillance and data exfiltration, and explore its infection chain and how to hunt for this threat using Splunk.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.