Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Sality

39
Global rank
62 infographic chevron month
Month rank
88 infographic chevron week
Week rank
0
IOCs

Sality is a highly sophisticated malware known for infecting executable files and rapidly spreading across networks. It primarily creates a peer-to-peer botnet that is used for malicious activities such as spamming, data theft, and downloading additional malware. Sality has strong persistence mechanisms, including disabling security software, making it difficult to remove. Its ability to spread quickly and silently, along with its polymorphic nature, allows it to evade detection by traditional antivirus solutions.

Botnet
Type
ex-USSR
Origin
1 June, 2003
First seen
10 August, 2026
Last seen

How to analyze Sality with ANY.RUN

Type
ex-USSR
Origin
1 June, 2003
First seen
10 August, 2026
Last seen

IOCs

IP addresses
48.209.138.189
57.153.246.3
184.86.251.27
48.192.1.65
142.251.110.94
142.251.150.119
151.101.193.91
151.101.1.91
34.107.243.93
151.101.129.91
142.251.14.94
142.251.110.139
142.251.13.94
23.11.40.157
23.52.181.141
34.54.88.138
34.120.208.123
172.217.208.95
142.250.154.97
85.17.167.196
Hashes
f073b23d47e6147dfef23e17170452edc57f09044fe64a872025c40ce6c70d59
81b2bd4ea98c8db66554fbc8d7637a1a69a130f331feb732b75caab4c4868fd5
337fa733767ef0fd0ae9adf061a38f5935257e34b75ef029ff02def23a16f3b3
6dd5ea53e5e8b2afa37b209831937165a092a1863aa75c1a2c6afeb8d67e2e0b
76c3656cc128f16e9c2bdda27896aada178d0902423bb4f4014ddc101502277c
7c2bacaba566bae80ebb209b80664616980b611770a7e78acdf9b60c396fee5a
b3e4e383491cfa05a6e5858dc73ac1a4018938ed5c15a0d37c708311bd252227
babeb483e7bc13a161427464ff4aa32b126458a9b7bd684609420f8d1a7cb6ab
fb69758c6600c18b5dba70d05af48463d183d2ff66177c5cb5efddd3218e1ceb
de1af3b87a33aa08369966e57403b2c34643335f40db514a7afc6b97b106c162
a65bbd2c04e427655a0c45d1f82f7685ada08bc874a74ab4e09037ec98ac9d5a
c5bc13ba28e3fad9bb69c25f294e5bebe315acc4947330a5cd0d2ce7928e2994
c49599398958207a50863ebc4e7e508a20b8551b440ae2d3d28ab90e317f5c12
5f3fc9163fe2e721c2aa420f3cee55276d56ee77858d4fbf09275009f74f2591
59bb133020146d20f0d963a09c0520755e8a49c60982dbc377b4072ee287be19
407728b9c1868b1b41651d9f4ba73f6ec824e21e296ccb5d53a089be4802f2af
f1bda6c63d6989632bf51771a73706154d20d3686092b4f1f866393debd5037b
0046a36b3f7ab1ff70620a8b32ba6f8a789d40ecd860bd003b3011fc436d4a1b
660704e30efa63fe14a6055be29e0064227817f3e4921c304bfb45606557a9d9
581e2ef4e785e2dbf50718a68487a5de833614b3f99df7e332c03e669aff920b
Domains
www.bing.com
google.com
activation-v2.sls.microsoft.com
settings-win.data.microsoft.com
dyna.wikimedia.org
detectportal.firefox.com
e15315.dsca.akamaiedge.net
ecs.office.com
incoming.telemetry.mozilla.org
firefox-settings-attachments.cdn.mozilla.net
mozilla.map.fastly.net
stats.g.doubleclick.net
temuaffiliateprogram.pxf.io
firefox.settings.services.mozilla.com
www.gstatic.com
ads-img.mozilla.org
push.services.mozilla.com
content-signature-2.cdn.mozilla.net
www.careerdesk.org
fonts.googleapis.com
URLs
http://www.msftconnecttest.com/connecttest.txt
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ba5566c774cc0139
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?23d0c0a1ba6b477b
http://ocsp.digicert.com/
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e4d5462edc08cd45
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6c80283bd36eff4c
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?93ce4f8b26023ea5
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbsnxliz3fu1wb6n1%2fe6xwn1b0jxiqqudiwawgbh3zfez70pn6odhb7tzrccealxhnr4eln54rgipwq89vq%3d
https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2025-10-19-08-10-44.chain
http://detectportal.firefox.com/canonical.html
https://ads.mozilla.org/v1/ads
https://firefox.settings.services.mozilla.com/v1/
https://safebrowsing.googleapis.com/v4/threatlistupdates:fetch?$ct=application/x-protobuf&key=aizasyc7jsptds3am4tpx4r3nxis7imjbc5dovo&$httpmethod=post&$req=chuke25hdmnsawvudc1hdxrvlwzmb3gajwgfeaeagwoncauqbhgbigmwmdeward4or0aahgjrzy6dciciaioaroncaeqarobcg0iaraggaeiazawmtabepniehocgakghe-qigigaigbgiciaxabghskdqgdeayyasidmdaxmaeqi8esggiycztxmakiaiackaeajwgheaeagwoncacqbhgbigmwmdewarda4riaahgjyupzisiciaioarolcakqarozcg0icraggaeiazawmtabecmaahgji9m7nsiciaioaq==
https://push.services.mozilla.com/
http://detectportal.firefox.com/success.txt?ipv4
https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/ms-language-packs/records/cfr-v1-en-us
https://incoming.telemetry.mozilla.org/submit/firefox-desktop/events/1/b088d146-335a-4794-9de0-8a01a93b7635
https://incoming.telemetry.mozilla.org/submit/firefox-desktop/metrics/1/4aa78f83-4552-4ac5-8d22-7328d28faa1a
https://www.google.com/complete/search?client=firefox&channel=ftr&q=
Last Seen at
Last Seen at

Recent blog posts

post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 326
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 14459
comments 0
post image
Safeguarding 200M Users: How ChongLuaDao Scal...
watchers 7510
comments 0

What is Sality malware?

Sality is a file-infecting virus and botnet malware first observed around 2003. It primarily targets Windows systems, infecting executable files (.exe) and spreading rapidly across networks and removable drives.

Over time, it has become highly persistent and adaptive, evading traditional security measures through polymorphism, constantly changing its code to avoid detection.

Similar to other botnet malware like Phorpiex and Mirai, Sality has infected hundreds of thousands of computers globally, creating a massive botnet. The malware operators use this network for various purposes, ranging from relatively "benign" tasks like generating spam to more malicious activities, such as distributing password stealers. In 2011, one of the programs distributed through the Sality botnet focused on stealing web credentials, particularly targeting Facebook and Google Blogger accounts.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Sality malware technical details

The primary functionality of Sality malware includes:

  • Spreads by infecting executable files and removable drives.
  • Uses polymorphic techniques to change its code with every infection, making it harder for antivirus software to detect or create consistent signatures.
  • Creates a P2P botnet for malicious activities like data theft and DDoS attacks.
  • Disables antivirus and firewall protections and uses rootkit techniques to hide its presence on the system.
  • Modifies the infected system’s hosts file to block access to security websites, preventing the user from downloading tools or updates that might detect or remove the virus.
  • Allows attackers to update and control infected systems remotely.

Sality connects infected machines to command and control (C2) servers or other infected systems within its botnet. This allows attackers to issue commands, download additional malware, and update the virus, ensuring it remains persistent and adaptive in its attack methods. Through this botnet, Sality can be used for a wide range of malicious activities, including:

  • Spamming
  • Distributed Denial of Service (DDoS) attacks
  • Data theft
  • Downloading additional malware

The data exchanged between the infected system and C2 servers is often encrypted, making it difficult for security experts to analyze the malware's activities.

Sality malware execution process

To see how Sality operates, let’s upload its sample into the ANY.RUN sandbox.

Once the Sality malware is executed, the stub decrypts and runs a secondary code segment known as the loader. The loader operates in a separate thread within the infected process and is responsible for executing the malware's main payload.

Sality actively targets security software by terminating antivirus-related processes and deleting files critical to system security. It may also modify system settings to reduce security levels and block the execution of security tools.

Sality malware in ANY.RUN Sality malware analyzed in the ANY.RUN sandbox

The malware is capable of stealing sensitive information, such as cached passwords and keystrokes, and can search for email addresses to send spam. It communicates with remote command and control (C2) servers, often utilizing a peer-to-peer (P2P) network to download additional malicious payloads or updates.

Modern Sality variants can form botnets, enabling attackers to control multiple infected machines. The botnets can be used for various malicious activities, including distributed denial-of-service (DDoS) attacks and further malware propagation.

Sality can also download and execute other malware, often through a preconfigured list of peers within its P2P network, allowing it to expand its capabilities and maintain persistence on infected systems.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Sality malware distribution methods

Sality malware employs several distribution methods that allow it to spread widely across networks and systems:

  • File infection: Sality primarily infects executable files (.exe) on infected machines, which helps it spread as these files are shared or transferred across systems.
  • Removable drives: The malware spreads through infected USB drives, external hard drives, and other removable media. When these drives are connected to other machines, Sality automatically infects them.
  • Network shares: It can spread across local networks by infecting shared folders and files, making it highly effective in corporate or organizational environments with multiple connected systems.
  • Peer-to-Peer (P2P) botnet: Sality creates a decentralized botnet, enabling it to communicate with other infected machines, spreading its payload and receiving updates from the attacker.
  • Self-replication: Once inside a system, Sality can modify system files, allowing it to replicate itself and infect more files and applications.

Gathering threat intelligence on Sality malware

To collect up-to-date intelligence on Sality and its latest variants, use Threat Intelligence Lookup. The service helps you search across a vast database of quality threat data sourced from millions of malware analysis sessions conducted in the ANY.RUN sandbox. It lets you use over 40 different search parameters and their combinations, including IPs, domains, command line artifacts, and process names.

Let's use a mutex fragment found in one Sality sample to find more samples. To do this, we'll submit the following query: syncObjectName:".EXEM_"

Sality query in ANY.RUN Sality mutex query in Threat Intelligence Lookup

The service returns one hundred sandbox sessions that we can explore further.

Get a 14-day free trial of Threat Intelligence Lookup along with the ANY.RUN sandbox

Conclusion

Sality’s ability to spread through infected files, disable security software, and form a botnet makes it a potential threat. Its focus on persistence and evading detection highlights the need for strong security measures. To effectively protect against Sality, it's important to use tools like malware sandboxes to thoroughly analyze suspicious files and detect threats early.

ANY.RUN offers a powerful solution, allowing users to safely examine and understand threats like Sality in real-time. By utilizing ANY.RUN, you can quickly detect and neutralize malware before it can cause harm to your systems.

Sign up for a free ANY.RUN account today and start analyzing malware with no limits!

HAVE A LOOK AT

Cerber screenshot
Cerber
cerber
Cerber is a Ransomware-as-a-Service (RaaS) that appeared in 2016, spread quickly and has been evolving since. It became well-known for its file encryption, offline capabilities, and sophisticated evasion techniques. It primarily targets enterprises, financial institutions, and government entities, encrypting their data and demanding ransom payments in Bitcoin. It also targets everyday users encrypting personal files (photos, documents) with the risk of their permanent loss.
Read More
INC Ransomware screenshot
INC Ransomware is a ransomware-as-a-service (RaaS) spotted in mid-2023. It targets industries like retail, real estate, finance, healthcare, and education, primarily in the U.S. and UK. It encrypts and exfiltrates data demanding a ransom. It employs advanced evasion techniques, destroys backup, and abuses legitimate system tools at all the stages of the kill chain.
Read More
EvilProxy screenshot
EvilProxy
evilproxy
EvilProxy is a phishing-as-a-service (PhaaS) platform that enables cybercriminals to bypass multi-factor authentication (MFA) and hijack user sessions. It leverages reverse proxy techniques to harvest credentials and session cookies, posing a serious threat to both individuals and enterprises.
Read More
RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More
Emmenhtal screenshot
Emmenhtal
emmenhtal
First identified in 2024, Emmenhtal operates by embedding itself within modified legitimate Windows binaries, often using HTA (HTML Application) files to execute malicious scripts. It has been linked to the distribution of malware such as CryptBot and Lumma Stealer. Emmenhtal is typically disseminated through phishing campaigns, including fake video downloads and deceptive email attachments.
Read More
zgRAT screenshot
zgRAT
zgrat
zgRAT is a malware known for its ability to infect systems and exfiltrate sensitive data to command-and-control (C2) servers. It is primarily distributed through loader malware, as well as phishing emails. zgRAT employs various advanced techniques, including process injection and code obfuscation, to evade detection and maintain persistence on infected systems. The malware can also spread via USB drives and uses popular messaging platforms like Telegram and Discord for data exfiltration.
Read More