← Back to SOC feed Coverage →

ThreatFox: SalatStealer IOCs

ioc-hunt HIGH ThreatFox
DeviceFileEvents
infostealeriocthreatfoxwin-salatstealer
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-07-13T23:00:01Z · Confidence: high

Hunt Hypothesis

This hunt detects adversary behavior where attackers deploy the SalatStealer infostealer to exfiltrate sensitive credentials and browser data using a specific set of known indicators of compromise. The SOC team should proactively search for these IOCs in Azure Sentinel to identify early-stage infections before they escalate into broader lateral movement or data theft incidents within the cloud environment.

IOC Summary

Malware Family: SalatStealer Total IOCs: 12 IOC Types: md5_hash, sha256_hash, sha1_hash

TypeValueThreat TypeFirst SeenConfidence
sha1_hash3cdd0d915cb1e61ab3d3145107fa4f3ed2800402payload2026-07-1395%
md5_hash66a00a43bf3626d775015cec5bb11d8fpayload2026-07-1395%
sha256_hash63423364abc33ebeda68838dd5605d60b883e21f3c29b1d98c927c75c8fb25d5payload2026-07-1395%
sha256_hashf36467769f8a9e79cf9342a01622cd6a099fb0104f20057c44fa8758823f1c6epayload2026-07-1395%
sha1_hash3fe86ee5b3223af55f54554f37003ab8a33e9b0epayload2026-07-1395%
md5_hash57cc2a7038bbd3e297c59144e2f3ed85payload2026-07-1395%
sha256_hash3ecae3266e1e24200de4a94f0ecdd504219d6de741af53340f65de9c8098fa01payload2026-07-1395%
sha1_hash9a2f37ff8710fe00d976d49179d9b9110a2b4e04payload2026-07-1395%
md5_hashfcc1104a5b4508c3f0c1c467d88941e2payload2026-07-1395%
sha256_hashd81d3e290d3e6f3f453a0e911069c95065ad52287bf2d46d4cbd12f268a423e7payload2026-07-1395%
sha1_hashfe3f06c245b31847c1cbddfa747c384ed355ce22payload2026-07-1395%
md5_hash2ea79a634c56d40338763ea276e596a0payload2026-07-1395%

KQL: Hash Hunt

// Hunt for files matching known malicious hashes
// Source: ThreatFox - SalatStealer
let malicious_hashes = dynamic(["3cdd0d915cb1e61ab3d3145107fa4f3ed2800402", "66a00a43bf3626d775015cec5bb11d8f", "63423364abc33ebeda68838dd5605d60b883e21f3c29b1d98c927c75c8fb25d5", "f36467769f8a9e79cf9342a01622cd6a099fb0104f20057c44fa8758823f1c6e", "3fe86ee5b3223af55f54554f37003ab8a33e9b0e", "57cc2a7038bbd3e297c59144e2f3ed85", "3ecae3266e1e24200de4a94f0ecdd504219d6de741af53340f65de9c8098fa01", "9a2f37ff8710fe00d976d49179d9b9110a2b4e04", "fcc1104a5b4508c3f0c1c467d88941e2", "d81d3e290d3e6f3f453a0e911069c95065ad52287bf2d46d4cbd12f268a423e7", "fe3f06c245b31847c1cbddfa747c384ed355ce22", "2ea79a634c56d40338763ea276e596a0"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
DeviceFileEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 5 specific false positive scenarios for the ThreatFox: SalatStealer IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:

Original source: https://threatfox.abuse.ch/browse/malware/win.salatstealer/