Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 7 hostnames
Sality is a long-running Windows malware family first discovered in 2003 and widely recognized as a polymorphic file infector and botnet/downloader platform.
Profile source: Mallory opens in a new tabSality
Sality is a long-running Windows malware family first discovered in 2003 and widely recognized as a polymorphic file infector and botnet/downloader platform. It infects Microsoft Windows system files, especially .EXE and .SCR executables, and spreads by infecting local files, replicating across network shares, and in some variants copying infected files to removable drives together with autorun.inf or related launcher files. Infected hosts join a decentralized peer-to-peer network over custom UDP-based communications, allowing bots to exchange signed URL lists and retrieve additional malware; later botnet versions also used attacker digital signatures to resist hostile takeover. Reported follow-on payloads distributed through Sality included spam relays, HTTP proxies, information stealers, website infectors, credential theft components, and distributed cracking tools.
The family evolved from earlier information-stealing variants into a more full-featured threat with process injection, in-memory loading, downloader functionality, anti-security behavior, and rootkit capabilities. Reported behaviors include injecting code into running processes, creating mutexes to avoid duplicate infection, dropping DLL components such as %SYSTEM%\\wmdrtc32.dll and compressed copies such as %SYSTEM%\\wmdrtc32.dl_, and in some variants dropping a randomly named driver into %SYSTEM%\\drivers and creating the service/rootkit device amsint32. Sality variants have been reported to terminate antivirus and security processes and services, block access to security vendor resources, weaken host defenses through registry modification, delete SafeBoot registry data to prevent Safe Mode booting, hide files, steal cached passwords and keystrokes, and exfiltrate sensitive data. Symantec reported a mutex named uxJLpe1m as a strong indicator of infection.
Sality has been described as highly resilient because it combines file infection with a decentralized P2P botnet architecture. The malware has been associated with botnet activity used to relay spam, proxy communications, exfiltrate data, compromise web servers, and coordinate distributed computing tasks such as password cracking. Symantec reported hundreds of thousands of infected machines in 2011, with active botnet versions 3 and 4, and the content states heavily affected countries included India, Vietnam, and Morocco. The malware has also been referenced in later telemetry as a persistent commodity threat and as resurging in 2025 command-and-control detections.
Observed indicators and artifacts mentioned in the content include the mutex uxJLpe1m; DLL paths such as %SYSTEM%\\wmdrtc32.dll and %SYSTEM%\\wmdrtc32.dl_; the rootkit/service name amsint32; and, in one 2019 contamination case involving Pinebook Pro boot partitions, files augjb.pif, kithj.pif, and autorun.inf with SHA256 hashes 6245eb607e53209126191e4b6cdf7d64f52394f6bc6a2a9529a28ed49be19c82, 37f1b6394a408e0a959b82ff118a526c1362b4ddc1db5da03c9ffa70acaebff4, and f5adcd0989f9c4033fcd214e8998dde85865c6bf178c4eaed94128e6f5389bd6 respectively; associated URLs hxxp://padrup[.]com[.]ds/sobaka1[.]gif and hxxp://paaaaad[.]fd[.]fd; and UDP contacts including 118.136.16.138:5614, 180.247.53.107:7866, 86.107.231.10:7534, 93.114.69.232:5684, 220.247.166.100:4492, 202.177.246.59:6715, 189.122.188.39:7538, 89.38.237.65:5064, 188.215.25.69:6310, 14.96.75.194:6130, 212.76.78.10:6260, 14.98.120.25:6740, 112.204.145.248:5300, and 200.8.145.17:6780.
C2 tracking
Derp observations, rolling seven-day window
Samples
12d3a6a9b75f9d08f55f343ddd6ba943bf3355fa337497d8e11ccbc4e099eb90 6326f4b04a4d106a635480f18858a823c6b2ac3f69e400e00c5fe8d46e63fc96 a6d21b2d35cf507e7be8f4d75826282d7771ea60676e4b10975987714e1ddaa6 c1b42ae2b52ec468c1d4b2917dd6781eccd5d5d779677a8c386da124e3e555d2 f7bbb86042531feded85a1abaf24998819f961ca0da4cd350fa27faae1e7063e 187979252bdf6e932753613b86202ce215132ccca8236215321c5c67b1de7875 3e68725df6872b5201f2462426b7b1b41aa8b3d7c1525b5be89f7e9d4032aac6 cfecc2bc043b4b5e3d412bea8664227cb437b0deb1e75657a933e38492a8a1c8 dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9 dd1bf6486965d831246279c59076aa1606cd3a81926cb6ff314c3f4ed3184455 Reported operators
Sality is a polymorphic file infector that was discovered in 2003; since then, it has been replaced by more advanced peer-to-peer (P2P) malware loaders.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.