da82df14a5412247654f68667f65d00e537f22d2d742ec39f6e0dce3831e44dc

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1970-Jan-01 00:00:00

Plugin Output

Suspicious PEiD Signature: PeStubOEP v1.x
HQR data file
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • sc.exe
Contains references to security software:
  • rshell.exe
May have dropper capabilities:
  • CurrentVersion\Run
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • -github.com
  • .eq.github.com
  • .eq.golang.org
  • .github.com
  • .hash.golang.org
  • .hash.net
  • 0github.com
  • 1github.com
  • 2github.com
  • 4github.com
  • 8github.com
  • 9github.com
  • GoneseeksyncStat.com
  • cloudflare-dns.com
  • enabledgithub.com
  • eq.github.com
  • eq.golang.org
  • github.com
  • golang.org
  • hash.golang.org
  • https://1.1.1.1
  • https://1.1.1.1/dns-query?name
  • https://cloudflare-dns.com
  • https://dns.google
  • https://github.com
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Suspicious The PE is possibly packed. Unusual section name found: .symtab
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • LoadLibraryExW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Malicious VirusTotal score: 55/69 (Scanned on 2026-08-13 13:22:03) ALYac: Gen:Variant.Tedy.932820
APEX: Malicious
AVG: Win32:SalatStealer-A [Pws]
AhnLab-V3: Trojan/Win.Generic.R727379
Alibaba: TrojanBanker:Win32/Vidar.418366b4
Antiy-AVL: Trojan/Win32.Vidar
Arcabit: Trojan.Tedy.DE3BD4
Avast: Win32:SalatStealer-A [Pws]
Avira: TR/W32.Evo
BitDefender: Gen:Variant.Tedy.932820
Bkav: W32.Malware.1566C4A1
CTX: exe.trojan.salat
ClamAV: Win.Malware.Salat-10058846-0
CrowdStrike: win/malicious_confidence_100% (W)
Cylance: Unsafe
Cynet: Malicious (score: 99)
DeepInstinct: MALICIOUS
DrWeb: Trojan.PWS.Salat.332
ESET-NOD32: WinGo/Agent.VO trojan
Elastic: Multi.Generic.Threat
Emsisoft: Gen:Variant.Tedy.932820 (B)
F-Secure: Trojan.TR/W32.Evo
Fortinet: W32/Agent.VO!tr
GData: Win32.Trojan.PSE.B4NNB3
Google: Detected
K7AntiVirus: Trojan ( 005c07f81 )
K7GW: Trojan ( 005c07f81 )
Kaspersky: Trojan-Banker.Win32.Agent.gen
Kingsoft: Win32.Trojan-Banker.Agent.gen
Lionic: Trojan.Win32.Agent.tt1u
Malwarebytes: Spyware.SalatStealer
MaxSecure: Trojan.Malware.140736129.susgen
McAfeeD: Trojan:Win/SalatStealer.AA
MicroWorld-eScan: Gen:Variant.Tedy.932820
Microsoft: Trojan:Win32/Vidar.MCQ!MTB
NANO-Antivirus: Trojan.Win32.Salat.lelhyf
Paloalto: generic.ml
Panda: Trj/CI.A
Rising: Stealer.Salat!1.13A22 (CLASSIC)
Sangfor: Infostealer.Win32.Vidar.Vb2j
SentinelOne: Static AI - Malicious PE
Skyhigh: BehavesLike.Win32.Generic.wh
Sophos: Troj/Salat-A
Symantec: ML.Attribute.HighConfidence
Tencent: Trojan.Win32.Stealer.16001830
TrellixENS: Artemis!EB99A50A1EB5
TrendMicro: TrojanSpy.Win32.SALATSTEALER.YXGCHZ
VIPRE: Gen:Variant.Tedy.932820
Varist: W32/Agent.MAZ.gen!Eldorado
VirIT: Trojan.Win32.SalatStlr.JIO
Webroot: Win.Trojan.Gen
Zillya: Trojan.Agent.Win32.4459491
ZoneAlarm: Troj/Salat-A
alibabacloud: Trojan:Multi/Rozena.SS
huorong: Trojan/Agent.e!crit

Hashes

MD5 eb99a50a1eb51e262e2cdcc2f9a8f3b9 🔍
SHA1 a879f9f0b775bf3f2786146e2e94e657626b18d5 🔍
SHA256 da82df14a5412247654f68667f65d00e537f22d2d742ec39f6e0dce3831e44dc 🔍
SHA3 c12f8f8650e764f363477f060c8c187579aa38a0d3eda0dae00a22b4ebf8e534 🔍
SSDeep 49152:VnAiTSCjvkHQVehfwJL0izh1J0Rh6FDHdCC+v/Npt7N7aLGEFO5DLE5dt/8mHH8:1BTSCvVB5mNpvaLudst//7Dp69By 🔍
Imports Hash 4f2f006e2ecf7172ad368f8289dc96c1 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0x8b
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 1970-Jan-01 00:00:00
PointerToSymbolTable 0xb21c00
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 3.0
SizeOfCode 0x4aae00
SizeOfInitializedData 0x53800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0006E610 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xa97000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 1.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0xb6f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b624e70218f8543ad2128a52dbd20ac6 🔍
SHA1 8da183b6ec0da199314174b059dc965e97bf7c30 🔍
SHA256 08b4179afd466233e826413d1953a5648d384aa4d528c30d584477cf377e59a9 🔍
SHA3 edeb57363b16c1bfba49d7b43c2882cb009d5ec939e7a267aafe3929f0a6758a 🔍
VirtualSize 0x4aac35
VirtualAddress 0x1000
SizeOfRawData 0x4aae00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.03804

.rdata

MD5 a268c9969fcddcc589d3ef2cbe478a8e 🔍
SHA1 8125492b23d26cb53086752dfb16f43729aa4e83 🔍
SHA256 563e551186d3750a46e57645e81b576579c3b519d0b9369e88cd14d113223402 🔍
SHA3 d128f8d3e8796409aa08539505e3d244fd7ac4b52cb3632f3e977df5fda683ce 🔍
VirtualSize 0x5ea2ec
VirtualAddress 0x4ac000
SizeOfRawData 0x5ea400
PointerToRawData 0x4ab200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.05715

.data

MD5 1398dddbdad29c4e18bd17148fb67d0e 🔍
SHA1 2336edf29f5a1ee032712c6e2b3716c41578b8d5 🔍
SHA256 68fd6438edf5e88d99ea7a4f66c02133469d7320e6a4e0b64971b9203dbbd22f 🔍
SHA3 993d6520a6fae6d676a59382620758f5c4f41e80ead1ec0878622059283ddf04 🔍
VirtualSize 0x9cec0
VirtualAddress 0xa97000
SizeOfRawData 0x53800
PointerToRawData 0xa95600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.24037

.idata

MD5 fb334e3a89c7a8e78ec6131ec15e85f1 🔍
SHA1 66fc22c9ff7f43727d5f95dbf0c0947f181aa655 🔍
SHA256 515582acb7fa04a8afccd359be8ac0e78f74316b05f52046ab9bcb0cf2cf79da 🔍
SHA3 60b25fa27ffcd449b4949207657953aabf265c1becd9610715f1ddadb01a98b2 🔍
VirtualSize 0x45e
VirtualAddress 0xb34000
SizeOfRawData 0x600
PointerToRawData 0xae8e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.88905

.reloc

MD5 2baa4328e94c8c14f2bc72e4e3c39da6 🔍
SHA1 70ba2c20838638efd950093cb11cb713ceabb220 🔍
SHA256 27e1fbbaed77b7a69cf68da46b89bb42c906f08e43de84843bae318d5de197b4 🔍
SHA3 5f78ad50269b2e9423268e800b9218751d1e2f86485d01a6f07f23e4f57be3f9 🔍
VirtualSize 0x38770
VirtualAddress 0xb35000
SizeOfRawData 0x38800
PointerToRawData 0xae9400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.65211

.symtab

MD5 07b5472d347d42780469fb2654b7fc54 🔍
SHA1 943ae54f4818e52409fbbaf60ffd71318d966b0d 🔍
SHA256 3e67f4a7d14b832ff2a2433e9cf0f6f5720821f67148a87c0ee2595a20c96c68 🔍
SHA3 a70a3e18515c06557b62676f2a8eb6d7d41962d8c9c7c49f4641c429cc65b977 🔍
VirtualSize 0x4
VirtualAddress 0xb6e000
SizeOfRawData 0x200
PointerToRawData 0xb21c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.0203931

Imports

KERNEL32.DLL WriteFile
WriteConsoleW
WerSetFlags
WerGetFlags
WaitForMultipleObjects
WaitForSingleObject
VirtualQuery
VirtualFree
VirtualAlloc
TlsAlloc
SwitchToThread
SuspendThread
SetWaitableTimer
SetUnhandledExceptionFilter
SetProcessPriorityBoost
SetEvent
SetErrorMode
SetConsoleCtrlHandler
ResumeThread
RaiseFailFastException
PostQueuedCompletionStatus
LoadLibraryW
LoadLibraryExW
SetThreadContext
GetThreadContext
GetSystemInfo
GetSystemDirectoryA
GetStdHandle
GetQueuedCompletionStatusEx
GetProcessAffinityMask
GetProcAddress
GetErrorMode
GetEnvironmentStringsW
GetCurrentThreadId
GetConsoleMode
FreeEnvironmentStringsW
ExitProcess
DuplicateHandle
CreateWaitableTimerExW
CreateThread
CreateIoCompletionPort
CreateFileA
CreateEventA
CloseHandle
AddVectoredExceptionHandler

Delayed Imports

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.