Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Sality

42
Global rank
106 infographic chevron month
Month rank
85 infographic chevron week
Week rank

Sality is a highly sophisticated malware known for infecting executable files and rapidly spreading across networks. It primarily creates a peer-to-peer botnet that is used for malicious activities such as spamming, data theft, and downloading additional malware. Sality has strong persistence mechanisms, including disabling security software, making it difficult to remove. Its ability to spread quickly and silently, along with its polymorphic nature, allows it to evade detection by traditional antivirus solutions.

Botnet
Type
ex-USSR
Origin
1 June, 2003
First seen
15 September, 2026
Last seen

How to analyze Sality with ANY.RUN

Type
ex-USSR
Origin
1 June, 2003
First seen
15 September, 2026
Last seen

IOCs

IP addresses
23.11.41.157
52.110.17.17
23.52.181.141
184.31.95.119
48.209.138.189
199.232.214.172
34.54.185.247
204.79.197.203
2.16.10.84
20.190.160.4
52.110.17.69
20.184.175.20
199.232.210.172
95.101.9.148
52.123.243.93
129.74.157.231
48.209.133.15
48.209.6.48
2.16.241.205
150.171.28.11
Hashes
5e9a7996fe94d7be10595d7133748760bf8348198b71b7a50fd8affaa980ac61
0698995af8458180d7849379f5a864bffe38126e5f18f3bacdd8215d0772c3f4
f3c59c4faef8b4e97ad0a9588db44affa0c10dae89d57e8f5aa4024499ba2f98
7eebee328baa84cadff1b35755afdfea8e186071faa2f725c8591145682a9f7a
33149c8d5b6e25a6783a1fcc99399d2846afe1b10f5ff5644201b80932ffc82c
3e336f2ac83dd771933401665fb6dbc444caef18ea795fa09472b480c945435d
17c972846e7994e3614a31abf09980ef6e85f8a3214e8848dc2f974959a4e4b7
4674cde188b9840083ae0d94b47fc8f3036f39e5f0b0e6722670f0ce0c9e5791
9d9d79be9f95e27e50eb9469850c84e72d8dcd2d30ba0e356fd8a9d560fb30ca
a2616a5223b9d2b8cd25dfe47d3ef4327ddf638a3246701e9b1cf5cad692d5c9
1d6ef441a13641aa02a121aca6ca1d7622454f3b3c17decf8ad7460d86a9b2ee
49f9014f930ca72524e3cb4ae15f5bdac8d4ef8a85489015a2f8da2f7d971706
bbc9a92abcc0bac517c65d9bbbfda05334613f2edcc008367a4aed28f95aac1d
5cd2c4d9f13524923046198c92213691539407e04fa520cdae9eade1bad3d91d
c59725f1c26c93071c1e99aab4b0dcfb920b3eb464e80f21ca3650dcac4587b2
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
f51a7acfffec56d6751561966d947d3fd199b74528c07dabdcf5fcb33d5b2e85
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
Domains
login.live.com
eip-terr-eu.cdp1.digicert.com.akahost.net
google.com
settings-win.data.microsoft.com
prod.ingestion-edge.prod.dataservices.mozgcp.net
dns.msftncsi.com
ecs.office.com
ctldl.windowsupdate.com
mrodevicemgr.officeapps.live.com
ocsp.digicert.com
oneocsp.microsoft.com
go.microsoft.com
officeclient.microsoft.com
self.events.data.microsoft.com
fs.microsoft.com
incoming.telemetry.mozilla.org
assets.msn.com
copilot.microsoft.com
www.bing.com
edge.microsoft.com
URLs
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9c90001b0522506d
http://ocsp.digicert.com/
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?887453bf39cad97c
http://www.msftconnecttest.com/connecttest.txt
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbsnxliz3fu1wb6n1%2fe6xwn1b0jxiqqudiwawgbh3zfez70pn6odhb7tzrccealxhnr4eln54rgipwq89vq%3d
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?45189e565d74478e
http://go.microsoft.com/fwlink/?linkid=252669&clcid=0x409
https://login.live.com/rst2.srf
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.22000.795.amd64fre.co_release.210604-1628&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=183&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=261405&deviceid=s%3adacd04bd-5869-44da-9fd2-107288ff2e26&app=fss&appver=10.0&maxshellversion=1000.22000.795.0&activehoursstart=7&minshellversion=1000.22000.795.0&securebootcapable=0&activehoursend=10&devicefamily=windows.desktop
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?589043eb440f4027
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?44f6da16bb727c44
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c6cdd4df92593aed
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?fb3bb25b658cfcc1
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceasmayxgarewr3pgr9svwmg%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaale%2bvmfuqbvyaaaaaaaas%3d
https://self.events.data.microsoft.com/onecollector/1.0/
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaaoqpopjdxrqzsaaaaaaa4%3d
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?0acae8f282e19397
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d7d28b08723a52f8
Last Seen at
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1292
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1586
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3183
comments 0

What is Sality malware?

Sality is a file-infecting virus and botnet malware first observed around 2003. It primarily targets Windows systems, infecting executable files (.exe) and spreading rapidly across networks and removable drives.

Over time, it has become highly persistent and adaptive, evading traditional security measures through polymorphism, constantly changing its code to avoid detection.

Similar to other botnet malware like Phorpiex and Mirai, Sality has infected hundreds of thousands of computers globally, creating a massive botnet. The malware operators use this network for various purposes, ranging from relatively "benign" tasks like generating spam to more malicious activities, such as distributing password stealers. In 2011, one of the programs distributed through the Sality botnet focused on stealing web credentials, particularly targeting Facebook and Google Blogger accounts.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Sality malware technical details

The primary functionality of Sality malware includes:

  • Spreads by infecting executable files and removable drives.
  • Uses polymorphic techniques to change its code with every infection, making it harder for antivirus software to detect or create consistent signatures.
  • Creates a P2P botnet for malicious activities like data theft and DDoS attacks.
  • Disables antivirus and firewall protections and uses rootkit techniques to hide its presence on the system.
  • Modifies the infected system’s hosts file to block access to security websites, preventing the user from downloading tools or updates that might detect or remove the virus.
  • Allows attackers to update and control infected systems remotely.

Sality connects infected machines to command and control (C2) servers or other infected systems within its botnet. This allows attackers to issue commands, download additional malware, and update the virus, ensuring it remains persistent and adaptive in its attack methods. Through this botnet, Sality can be used for a wide range of malicious activities, including:

  • Spamming
  • Distributed Denial of Service (DDoS) attacks
  • Data theft
  • Downloading additional malware

The data exchanged between the infected system and C2 servers is often encrypted, making it difficult for security experts to analyze the malware's activities.

Sality malware execution process

To see how Sality operates, let’s upload its sample into the ANY.RUN sandbox.

Once the Sality malware is executed, the stub decrypts and runs a secondary code segment known as the loader. The loader operates in a separate thread within the infected process and is responsible for executing the malware's main payload.

Sality actively targets security software by terminating antivirus-related processes and deleting files critical to system security. It may also modify system settings to reduce security levels and block the execution of security tools.

Sality malware in ANY.RUN Sality malware analyzed in the ANY.RUN sandbox

The malware is capable of stealing sensitive information, such as cached passwords and keystrokes, and can search for email addresses to send spam. It communicates with remote command and control (C2) servers, often utilizing a peer-to-peer (P2P) network to download additional malicious payloads or updates.

Modern Sality variants can form botnets, enabling attackers to control multiple infected machines. The botnets can be used for various malicious activities, including distributed denial-of-service (DDoS) attacks and further malware propagation.

Sality can also download and execute other malware, often through a preconfigured list of peers within its P2P network, allowing it to expand its capabilities and maintain persistence on infected systems.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Sality malware distribution methods

Sality malware employs several distribution methods that allow it to spread widely across networks and systems:

  • File infection: Sality primarily infects executable files (.exe) on infected machines, which helps it spread as these files are shared or transferred across systems.
  • Removable drives: The malware spreads through infected USB drives, external hard drives, and other removable media. When these drives are connected to other machines, Sality automatically infects them.
  • Network shares: It can spread across local networks by infecting shared folders and files, making it highly effective in corporate or organizational environments with multiple connected systems.
  • Peer-to-Peer (P2P) botnet: Sality creates a decentralized botnet, enabling it to communicate with other infected machines, spreading its payload and receiving updates from the attacker.
  • Self-replication: Once inside a system, Sality can modify system files, allowing it to replicate itself and infect more files and applications.

Gathering threat intelligence on Sality malware

To collect up-to-date intelligence on Sality and its latest variants, use Threat Intelligence Lookup. The service helps you search across a vast database of quality threat data sourced from millions of malware analysis sessions conducted in the ANY.RUN sandbox. It lets you use over 40 different search parameters and their combinations, including IPs, domains, command line artifacts, and process names.

Let's use a mutex fragment found in one Sality sample to find more samples. To do this, we'll submit the following query: syncObjectName:".EXEM_"

Sality query in ANY.RUN Sality mutex query in Threat Intelligence Lookup

The service returns one hundred sandbox sessions that we can explore further.

Get a 14-day free trial of Threat Intelligence Lookup along with the ANY.RUN sandbox

Conclusion

Sality’s ability to spread through infected files, disable security software, and form a botnet makes it a potential threat. Its focus on persistence and evading detection highlights the need for strong security measures. To effectively protect against Sality, it's important to use tools like malware sandboxes to thoroughly analyze suspicious files and detect threats early.

ANY.RUN offers a powerful solution, allowing users to safely examine and understand threats like Sality in real-time. By utilizing ANY.RUN, you can quickly detect and neutralize malware before it can cause harm to your systems.

Sign up for a free ANY.RUN account today and start analyzing malware with no limits!

HAVE A LOOK AT

Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
Mirage2FA screenshot
Mirage2FA
mirage2fa
Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.
Read More
BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More
Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
Interlock screenshot
Interlock
interlock
Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.
Read More
BQTLock screenshot
BQTLock
bqtlock baqiyatlock
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.
Read More