This hunt targets adversary behavior consistent with the SalatStealer infostealer, specifically identifying active infections through a curated set of 15 known indicators of compromise (IOCs). Proactive hunting for these signatures in Azure Sentinel is critical to rapidly detect and contain credential theft campaigns before they escalate into broader lateral movement or data exfiltration incidents.
Malware Family: SalatStealer Total IOCs: 15 IOC Types: sha256_hash, md5_hash, sha1_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| sha256_hash | b177b510a76386fddb69800592dbb85ccf5d1aada1059b721a061189c92300e0 | payload | 2026-07-02 | 95% |
| sha1_hash | 501efd44aeb1f6827dbc83c2d84eb6be1171a41e | payload | 2026-07-02 | 95% |
| md5_hash | d8249352b400ff101c4598cd08d2d9e6 | payload | 2026-07-02 | 95% |
| md5_hash | 4e9def021931e28ae897bcb608b537db | payload | 2026-07-02 | 95% |
| md5_hash | 6b98948154e2e58689c535cbed1cb0e5 | payload | 2026-07-02 | 95% |
| sha256_hash | 7e7ef5b1cc82799cff8ac357bc6f7b3e5c1bfc4275b0c93da61db7e458d611e8 | payload | 2026-07-02 | 95% |
| sha1_hash | ae588dce549e626c8e4f48a59a774d6340f6d9e0 | payload | 2026-07-02 | 95% |
| sha256_hash | 1c4948cac8289b0f94ce49f76bc5aec8024c9a7b1d609bc1f2fc6ae0b52c2456 | payload | 2026-07-02 | 95% |
| sha1_hash | c1fde6836c51f4a23cd636c571f4124ab506d309 | payload | 2026-07-02 | 95% |
| md5_hash | 1204670b07905cd586d001137e3c690f | payload | 2026-07-02 | 95% |
| md5_hash | 9992290015ca21f58eab64953830a94d | payload | 2026-07-02 | 95% |
| sha256_hash | 78695b566b8aff8f42cccc5e264693a64582fb29d814650830a16a8a210e82ba | payload | 2026-07-02 | 95% |
| sha1_hash | df112662c9613fc8a7459bc31708d9d96278d4dc | payload | 2026-07-02 | 95% |
| sha256_hash | eee97b264c2b0b6488dcf397800e16ac196ec495a6abd3c2623a020c36acdfd2 | payload | 2026-07-02 | 95% |
| sha1_hash | 26dc16413bce56a9da5deae93a6fcf1e53dcec7d | payload | 2026-07-02 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - SalatStealer
let malicious_hashes = dynamic(["b177b510a76386fddb69800592dbb85ccf5d1aada1059b721a061189c92300e0", "501efd44aeb1f6827dbc83c2d84eb6be1171a41e", "d8249352b400ff101c4598cd08d2d9e6", "4e9def021931e28ae897bcb608b537db", "6b98948154e2e58689c535cbed1cb0e5", "7e7ef5b1cc82799cff8ac357bc6f7b3e5c1bfc4275b0c93da61db7e458d611e8", "ae588dce549e626c8e4f48a59a774d6340f6d9e0", "1c4948cac8289b0f94ce49f76bc5aec8024c9a7b1d609bc1f2fc6ae0b52c2456", "c1fde6836c51f4a23cd636c571f4124ab506d309", "1204670b07905cd586d001137e3c690f", "9992290015ca21f58eab64953830a94d", "78695b566b8aff8f42cccc5e264693a64582fb29d814650830a16a8a210e82ba", "df112662c9613fc8a7459bc31708d9d96278d4dc", "eee97b264c2b0b6488dcf397800e16ac196ec495a6abd3c2623a020c36acdfd2", "26dc16413bce56a9da5deae93a6fcf1e53dcec7d"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: SalatStealer IOCs detection rule in an enterprise environment, including suggested filters and exclusions:
Endpoint Protection Signature Updates
C:\Program Files\CrowdStrike\fsagent.exe or MsMpEng.exe) and the file path resides within the vendor’s dedicated update folder (e.g., \Windows\SoftwareDistribution\Download or \CrowdStrike\Logs).IT Admin Manual Artifact Analysis
SG-Security-Analysts or IT-Admins) AND file paths located in designated analysis directories (e.g., C:\Users\Public\Documents\MalwareSamples or the user’s Desktop).Scheduled Vulnerability Scanning Jobs