File classification
Confirmed malware sample
Classification is bounded to named stored sources.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type md5 · source MalwareBazaar
KNOWN MALWARE — Salatstealer
Malware file investigation
MalwareBazaar reported this EXE sample as confirmed malware. SalatStealer is the stored family attribution. 1 distinct source and 2 verified alternate digests are available. The hash identifies file bytes; it does not prove the file executed in any environment.
File classification
Confirmed malware sample
Classification is bounded to named stored sources.
Malware family
SalatStealer
A source-provided label, not a Forensia-inferred attribution.
File profile
MD5 · EXE
Credential or information theft
Source corroboration
1 distinct connector
18 polling citations are shown separately and not treated as independent evidence.
Related evidence
2 same-file digest variants
Only persisted same-file edges, YARA matches, and exact report mentions count here; generic file-type co-tags are excluded.
Observation window
2026-09-06 → 2026-09-06
These are first and last local feed observations, not file creation or execution times.
Findings stay bounded to named sources and observable infrastructure.
Neighborhood topology. Open the graph for interactive pivots.
Loading connected indicators, reports and entities.
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
SHA-256 ee27a24d9413d94c06b34f78ca7a8f08bac18391cd06d3a2dd7355897c1fe91e, SHA-1 f9aebdae36f1407cd7fa11aff61c13337c3a5a4d
Persisted related_hash edges from the ingestion record
These hashes identify the same reported file, not a broader malware campaign or operator.