This hunt detects adversary behavior where attackers deploy the SalatStealer infostealer to exfiltrate sensitive credentials and browser data using a specific set of known indicators of compromise. The SOC team should proactively search for these IOCs in Azure Sentinel to identify early-stage infections before they escalate into broader lateral movement or data theft incidents within the cloud environment.
Malware Family: SalatStealer Total IOCs: 12 IOC Types: md5_hash, sha256_hash, sha1_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| sha1_hash | 3cdd0d915cb1e61ab3d3145107fa4f3ed2800402 | payload | 2026-07-13 | 95% |
| md5_hash | 66a00a43bf3626d775015cec5bb11d8f | payload | 2026-07-13 | 95% |
| sha256_hash | 63423364abc33ebeda68838dd5605d60b883e21f3c29b1d98c927c75c8fb25d5 | payload | 2026-07-13 | 95% |
| sha256_hash | f36467769f8a9e79cf9342a01622cd6a099fb0104f20057c44fa8758823f1c6e | payload | 2026-07-13 | 95% |
| sha1_hash | 3fe86ee5b3223af55f54554f37003ab8a33e9b0e | payload | 2026-07-13 | 95% |
| md5_hash | 57cc2a7038bbd3e297c59144e2f3ed85 | payload | 2026-07-13 | 95% |
| sha256_hash | 3ecae3266e1e24200de4a94f0ecdd504219d6de741af53340f65de9c8098fa01 | payload | 2026-07-13 | 95% |
| sha1_hash | 9a2f37ff8710fe00d976d49179d9b9110a2b4e04 | payload | 2026-07-13 | 95% |
| md5_hash | fcc1104a5b4508c3f0c1c467d88941e2 | payload | 2026-07-13 | 95% |
| sha256_hash | d81d3e290d3e6f3f453a0e911069c95065ad52287bf2d46d4cbd12f268a423e7 | payload | 2026-07-13 | 95% |
| sha1_hash | fe3f06c245b31847c1cbddfa747c384ed355ce22 | payload | 2026-07-13 | 95% |
| md5_hash | 2ea79a634c56d40338763ea276e596a0 | payload | 2026-07-13 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - SalatStealer
let malicious_hashes = dynamic(["3cdd0d915cb1e61ab3d3145107fa4f3ed2800402", "66a00a43bf3626d775015cec5bb11d8f", "63423364abc33ebeda68838dd5605d60b883e21f3c29b1d98c927c75c8fb25d5", "f36467769f8a9e79cf9342a01622cd6a099fb0104f20057c44fa8758823f1c6e", "3fe86ee5b3223af55f54554f37003ab8a33e9b0e", "57cc2a7038bbd3e297c59144e2f3ed85", "3ecae3266e1e24200de4a94f0ecdd504219d6de741af53340f65de9c8098fa01", "9a2f37ff8710fe00d976d49179d9b9110a2b4e04", "fcc1104a5b4508c3f0c1c467d88941e2", "d81d3e290d3e6f3f453a0e911069c95065ad52287bf2d46d4cbd12f268a423e7", "fe3f06c245b31847c1cbddfa747c384ed355ce22", "2ea79a634c56d40338763ea276e596a0"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the ThreatFox: SalatStealer IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Endpoint Protection Scanning of Quarantined Archives
C:\Quarantine directory. This process unpacks and analyzes thousands of previously flagged files, triggering network connections to the specific IOCs (IP addresses/URLs) associated with SalatStealer as part of its heuristic reputation check, even though no active infection exists on the host.svc-crowdstrike or LocalSystem) specifically when accessing paths containing \Quarantine\, \Temp\, or \Updates\. Additionally, exclude traffic where the parent process is known to be the antivirus engine itself.IT Asset Management Software Updates
svc-ivanti-agent) and exclude network connections to these IOCs if the destination port is standard for software distribution (e.g., TCP 443, 80) and the user agent string matches the known patching tool signature.**Scheduled Backup Jobs Accessing