MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e8f0fa023b588637fb33b951933a20d94ccb8a98f0e684fca92e07f216d87c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SalatStealer


Vendor detections: 16


Intelligence 16 IOCs YARA 11 File information Comments

SHA256 hash: 0e8f0fa023b588637fb33b951933a20d94ccb8a98f0e684fca92e07f216d87c6
SHA3-384 hash: 2c44ac404ee9a486b0998d7a7483980a8029cd62a8fa3b79c26009e87b0ab62241e5edaa9b2b4b2cec9e715f9ff4b7de
SHA1 hash: 92bd064212033d96c4453857e5dc78d5974850c6
MD5 hash: b1a031ea42ce7c7d3afc496f862cd155
humanhash: georgia-uniform-violet-skylark
File name:Exclusion.exe
Download: download sample
Signature SalatStealer
File size:14'336 bytes
First seen:2026-01-03 13:25:32 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'125 x AgentTesla, 20'148 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 384:i/VKFY/GpC99FCHxRWmZa6m2a2CfOaM8xKVheWGh:i/VSY+4RCRC6mGC3xKvG
Threatray 438 similar samples on MalwareBazaar
TLSH T1C6523B0AF3DCAA62E5AE42341832031A73B1E16A9825D75E5CC840AD6F3738C17937F9
TrID 67.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
9.7% (.EXE) Win64 Executable (generic) (10522/11/4)
6.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.1% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter burger
Tags:exe SalatStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
111
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Exclusion.exe
Verdict:
Malicious activity
Analysis date:
2026-01-03 13:28:45 UTC
Tags:
susp-powershell loader salatstealer stealer auto-sch auto-reg telegram auto-startup ms-smartcard ims-api generic

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
90.2%
Tags:
obfuscate xtreme shell
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Creating a process from a recently created file
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug base64 cmd fingerprint lolbin lolbin obfuscated packed schtasks unsafe
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-12-30T08:38:00Z UTC
Last seen:
2026-01-04T01:46:00Z UTC
Hits:
~100
Detections:
PDM:Trojan.Win32.Generic Trojan-Downloader.Win32.PsDownload.sb HEUR:Trojan-Downloader.MSIL.PsDownload.gen
Result
Threat name:
Clipboard Hijacker, Salat Stealer
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Creates multiple autostart registry keys
Encrypted powershell cmdline option found
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Uses schtasks.exe or at.exe to add and modify task schedules
Uses the Telegram API (likely for C&C communication)
Yara detected Clipboard Hijacker
Yara detected Salat Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1844174 Sample: Exclusion.exe Startdate: 03/01/2026 Architecture: WINDOWS Score: 100 78 api.telegram.org 2->78 80 goooooogk.cfd 2->80 82 dns.google 2->82 96 Suricata IDS alerts for network traffic 2->96 98 Found malware configuration 2->98 100 Antivirus detection for URL or domain 2->100 104 10 other signatures 2->104 10 Exclusion.exe 14 9 2->10         started        15 WindowsUpdate.exe 2->15         started        17 svchost.exe 1 1 2->17         started        19 2 other processes 2->19 signatures3 102 Uses the Telegram API (likely for C&C communication) 78->102 process4 dnsIp5 90 goooooogk.cfd 91.149.219.47, 443, 49725 GECKONET-ASPL Poland 10->90 70 C:\Users\user\AppData\...\Z3WPUUMQVW9_1.exe, PE32+ 10->70 dropped 72 C:\Users\user\AppData\...\Z3WPUUMQVW9.exe, PE32 10->72 dropped 74 C:\Users\user\AppData\...\exclude_c_drive.ps1, Unicode 10->74 dropped 76 C:\Users\user\AppData\...xclusion.exe.log, CSV 10->76 dropped 126 Suspicious powershell command line found 10->126 128 Encrypted powershell cmdline option found 10->128 130 Bypasses PowerShell execution policy 10->130 21 cmd.exe 1 10->21         started        23 cmd.exe 10->23         started        25 powershell.exe 23 10->25         started        34 2 other processes 10->34 132 Multi AV Scanner detection for dropped file 15->132 28 schtasks.exe 15->28         started        30 conhost.exe 15->30         started        92 127.0.0.1 unknown unknown 17->92 94 8.8.4.4, 443, 58416 GOOGLEUS United States 19->94 32 conhost.exe 19->32         started        file6 signatures7 process8 signatures9 36 Z3WPUUMQVW9.exe 2 4 21->36         started        41 conhost.exe 21->41         started        43 Z3WPUUMQVW9_1.exe 23->43         started        45 conhost.exe 23->45         started        122 Found many strings related to Crypto-Wallets (likely being stolen) 25->122 124 Loading BitLocker PowerShell Module 25->124 47 conhost.exe 25->47         started        49 conhost.exe 28->49         started        51 conhost.exe 34->51         started        53 conhost.exe 34->53         started        process10 dnsIp11 84 dns.google 8.8.8.8, 443, 49753, 58415 GOOGLEUS United States 36->84 86 172.67.190.135, 443, 58418, 61601 CLOUDFLARENETUS United States 36->86 64 C:\Users\user\AppData\...\SgrmBroker.exe, PE32 36->64 dropped 66 C:\...\YUOhdNQSTwgHnGBp.exe, PE32 36->66 dropped 106 Antivirus detection for dropped file 36->106 108 Multi AV Scanner detection for dropped file 36->108 110 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 36->110 112 Found many strings related to Crypto-Wallets (likely being stolen) 36->112 55 SgrmBroker.exe 36->55         started        88 api.telegram.org 149.154.166.110, 443, 49729, 49730 TELEGRAMRU United Kingdom 43->88 68 C:\Users\user\AppData\...\WindowsUpdate.exe, PE32+ 43->68 dropped 114 Creates multiple autostart registry keys 43->114 116 Uses schtasks.exe or at.exe to add and modify task schedules 43->116 58 schtasks.exe 43->58         started        60 conhost.exe 43->60         started        file12 signatures13 process14 signatures15 118 Antivirus detection for dropped file 55->118 120 Multi AV Scanner detection for dropped file 55->120 62 conhost.exe 58->62         started        process16
Verdict:
inconclusive
YARA:
6 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.50 Win 32 Exe x86
Threat name:
Win32.Trojan.SalatStealer
Status:
Malicious
First seen:
2025-12-30 15:38:26 UTC
File Type:
PE (.Net Exe)
Extracted files:
1
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Unpacked files
SH256 hash:
0e8f0fa023b588637fb33b951933a20d94ccb8a98f0e684fca92e07f216d87c6
MD5 hash:
b1a031ea42ce7c7d3afc496f862cd155
SHA1 hash:
92bd064212033d96c4453857e5dc78d5974850c6
Malware family:
SalatStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

SalatStealer

Executable exe 0e8f0fa023b588637fb33b951933a20d94ccb8a98f0e684fca92e07f216d87c6

(this sample)

Comments