Sality Residual Infection After Disruption
Executive Summary
What happened: CrowdStrike reported on 1 September 2026 that an international public-private operation disrupted Sality's operator-controlled payload channel on 31 August, while the U.S. Department of Justice and Europol independently confirmed the seizures and sinkholing. The action neutralized new operator instructions but did not remove malware already resident on endpoints; CrowdStrike observed about 33,000 infected systems in its telemetry, and Europol said millions of unique IP addresses had been linked to the botnet over its long history.
How Sality works: Sality is a polymorphic Windows file infector with decentralized peer-to-peer protocol variants. It infects executable files, spreads through network shares and removable media, and uses its peer mesh to obtain URL packs and secondary payloads. The disrupted infrastructure included an operator-controlled lighthouse at 188.166.101.148. CrowdStrike states that any UDP communication to this address after the takedown is confirmation that the source system remains infected. Historical modules included credential theft, DDoS capability, and the EggJagger clipboard hijacker, which replaced cryptocurrency addresses copied by a victim.
Why detection lives in network and endpoint evidence: Q01 is the strongest keeper because the post-disruption lighthouse destination is now an inert, high-confidence infection signal. Q02 finds lookups to the final URL-pack hosts, while Q03 looks for executable launch from network or non-system volumes consistent with documented propagation. The destination and domain set can age or be reassigned, so responders must bind a hit to endpoint process, file-integrity, and memory evidence rather than treating a list match as eradication.
Operational limit: The portable query set cannot prove file infection, memory-resident peer state, or successful payload delivery. Those require host acquisition, known-good executable comparison, memory scanning, and tenant-confirmed event semantics. All CQL here is static-reviewed only: no Falcon tenant parsed the searches, no positive fixture or benign baseline ran, no schedule was created, and no prevention control was enabled.
| Priority | Why now | Coverage delivered | Key limitation |
|---|---|---|---|
| Find and contain independently corroborated behavior | Current 2026 technical and government reporting | 3 CQL designs with native pivots | Static-only; tenant and host-result semantics unverified |
Source and Claim Review
Current-run sanitized plain-text snapshots were hashed before assembly. Every source was treated as untrusted data; no embedded instruction, command, code, payload, or destination was executed.
| ID | Publisher | Tier | Independence | Accessed | Status |
|---|---|---|---|---|---|
| S01 | CrowdStrike | T1 | crowdstrike | 2026-09-06T11:06:41Z | successful sanitized technical extraction |
| S02 | U.S. Department of Justice | T1 | us-doj | 2026-09-06T11:06:41Z | successful sanitized government release |
| S03 | Europol | T1 | europol | 2026-09-06T11:06:41Z | successful sanitized government release |
| S04 | Microsoft Learn | T1 | microsoft | 2026-09-06T11:06:41Z | successful authoritative control summary |
| S05 | Microsoft Learn | T1 | microsoft | 2026-09-06T11:06:41Z | successful authoritative control summary |
| S06 | NIST | T1 | nist | 2026-09-06T11:06:41Z | successful authoritative guidance summary |
| Claim | Statement | Sources | Confidence |
|---|---|---|---|
| C01 | CrowdStrike reported the operator channel disrupted on 31 August 2026 but stated existing infections remain and require remediation. | S01 | high |
| C02 | CrowdStrike observed about 33,000 infected endpoints; Europol described a two-decade botnet historically linked to millions of unique IP addresses. | S01, S03 | high |
| C03 | Sality is a polymorphic Windows file infector that spreads through network shares and removable media and uses decentralized peer-to-peer protocols. | S01, S02, S03 | high |
| C04 | Post-disruption UDP traffic to lighthouse 188.166.101.148 confirms a residual Sality infection according to CrowdStrike. | S01 | high |
| C05 | The final observed URL packs referenced a finite set of payload-distribution hostnames that are useful for historical hunt and enrichment, not automatic blocking. | S01 | high |
| C06 | Sality has delivered credential theft, DDoS, and clipboard-hijacking capabilities, but detection alone does not prove a specific module executed. | S01, S02 | high |
| C07 | Microsoft application control guidance recommends inventory, audit, pilot, enforcement, and recovery planning. | S04 | high |
| C08 | Microsoft Defender Network Protection supports audit and block modes, with platform and cloud-protection prerequisites. | S05 | high |
| C09 | NIST malware guidance emphasizes preparation, detection and analysis, containment, eradication, and recovery. | S06 | high |
Hunt Brief and Attack Chain
The scaffold separates discrete endpoint and network observables from host-acquisition gaps. Each queryable hypothesis names an event and safe validation plan.
| Step | Claims | Behavior | Platform | Goal |
|---|---|---|---|---|
| 1 | C03 | infects or replaces Windows executable files | Windows | Find executable activity outside trusted baseline |
| 2 | C03 | propagates through network shares and removable media | Windows | Find execution from non-system and UNC paths |
| 3 | C03 | joins decentralized peer-to-peer control mesh | Windows | Find network evidence tied to endpoint process context |
| 4 | C04 | contacts operator-controlled lighthouse | Windows | Identify confirmed residual infection after disruption |
| 5 | C05 | retrieves URL packs for secondary payloads | Windows | Find DNS history for final distribution hosts |
| ID | Behavior | Telemetry | Use | Lookback | Validation |
|---|---|---|---|---|---|
| H01 | Post-disruption Sality lighthouse communication | NetworkConnectIP4 | alert-candidate | 30d | A hit to the disclosed inert lighthouse should be preserved and corroborated on the host; validate with a non-routable fixture and a 30-day destination baseline. |
| H02 | DNS lookup to final Sality URL-pack hosts | DnsRequest | hunt | 90d | Verify a DNS-only test against an analyst-controlled domain and baseline historical reuse before escalation. |
| H03 | Executable launch from network or non-system volume | ProcessRollup2 | hunt | 30d | Run an inert signed executable from a lab removable drive and baseline enterprise software distribution paths. |
| H04 | Polymorphic file infection or memory-resident Sality keys | host acquisition and YARA | gap | N/A | Use approved offline memory and known-good executable comparison; portable Falcon fields cannot prove infection. |
Affected surface and telemetry
Windows endpoints with Falcon process, file, DNS, and network telemetry are in scope. Proxy, IPv6, resolver, process-context, browser, memory, and file-integrity evidence remain repository- and tenant-dependent.
Consolidated IOC Table
| ID | Type | Value | Source | Use |
|---|---|---|---|---|
| I01 | ipv4 | 188.166.101.148 | S01 | detect and investigate residual infection |
| I02 | domain | theunforgiven.p8.hu | S01 | historical hunt and enrichment |
| I03 | domain | painelwebradiodigital.awardspace.info | S01 | historical hunt and enrichment |
| I04 | domain | sgwebdesigner.free.fr | S01 | historical hunt and enrichment |
| I05 | domain | yonelco.com | S01 | historical hunt and enrichment |
| I06 | domain | pozdravizbeograda.com | S01 | historical hunt and enrichment |
| I07 | domain | highclass.atspace.com | S01 | historical hunt and enrichment |
| I08 | domain | situluimihai.3x.ro | S01 | historical hunt and enrichment |
| I09 | domain | gatheredovertime.com | S01 | historical hunt and enrichment |
| I10 | domain | imagebucket.biz | S01 | historical hunt and enrichment |
Values are defanged only in analyst handling; the machine-readable appendix retains exact source text for matching. Revalidate ownership and time context before blocking.
ATT&CK Mapping
Every technique row is an analyst inference from source-backed behavior, not a vendor attribution statement.
| Tactic | Technique | Name | Behavior | Basis | Sources |
|---|---|---|---|---|---|
| Command and Control | T1095 | Non-Application Layer Protocol | peer-to-peer malware communications and UDP lighthouse traffic | analyst inference | S01 |
| Lateral Movement | T1021.002 | SMB/Windows Admin Shares | propagation through network shares | analyst inference | S01,S02 |
| Initial Access | T1091 | Replication Through Removable Media | propagation through removable media | analyst inference | S01,S02 |
| Defense Evasion | T1027.013 | Encrypted/Encoded File | polymorphic mutation of infected executable files | analyst inference | S01 |
| Command and Control | T1105 | Ingress Tool Transfer | URL packs and secondary payload delivery | analyst inference | S01 |
Native / Non-CQL Hunts
| Hunt | Log source | Logic | Response |
|---|---|---|---|
| Memory-resident Sality key hunt | Approved memory-acquisition workflow | Scan acquired memory with the vendor-published Sality YARA rules and preserve matching offsets; do not execute samples. | Escalate only after analyst review and corroborating host/network evidence. |
| Executable integrity review | Falcon file events plus enterprise software inventory | Compare executable hashes and signatures against known-good deployment baselines on a Q01 host; prioritize recent mutations and shared/removable locations. | Rebuild or restore from trusted media when file infection is confirmed. |
| Peer and URL-pack reconstruction | Firewall, DNS, and proxy logs | Pivot 90 days from the host and disclosed values; inspect UDP peers and URL-pack host access without contacting any destination. | Preserve raw logs and scope peer hosts before containment changes. |
CrowdStrike LogScale CQL Hunt Queries
Looks for: IPv4 network connections to the operator lighthouse disclosed after the takedown. Accomplishes: turns an inert post-disruption destination into the pack's strongest residual-infection signal while retaining process and protocol context.
// HUNT: Post-disruption Sality lighthouse traffic // HYPOTHESIS: H01 // USE: alert-candidate // MITRE: T1095 // CONF: high // FP: low // COST: low // TIMEFRAME: 30d — bounded analyst review window // REQUIRES: NetworkConnectIP4; RemoteAddressIP4, Protocol, ContextBaseFileName, ContextProcessId_decimal // FALSE POSITIVES: authorized research replays or preserved historical telemetry // TUNING: exclude only documented lab sensors after owner and time-window confirmation // VALIDATION: STATIC-ONLY #event_simpleName = NetworkConnectIP4 | test(@timestamp >= now() - 2592000000) | RemoteAddressIP4 = 188.166.101.148 | table([@timestamp, ComputerName, UserName, ContextBaseFileName, ContextProcessId_decimal, Protocol, RemoteAddressIP4, RemotePort, aid]) | sort(@timestamp, order=desc, limit=1000)
Looks for: DNS requests to the last URL-pack hosts documented before disruption. Accomplishes: provides a bounded historical pivot for secondary-payload delivery while making hostname reuse and resolver attribution explicit analyst checks.
// HUNT: Final Sality URL-pack domain lookups // HYPOTHESIS: H02 // USE: hunt // MITRE: T1105 // CONF: medium // FP: medium // COST: low // TIMEFRAME: 90d — bounded analyst review window // REQUIRES: DnsRequest; DomainName, ContextBaseFileName, ContextProcessId_decimal // FALSE POSITIVES: security research, historical sinkhole traffic, or reassigned hosting // TUNING: confirm registration and time context; exclude only owner-approved research systems // VALIDATION: STATIC-ONLY #event_simpleName = DnsRequest | test(@timestamp >= now() - 7776000000) | DomainName = /^(?:theunforgiven\.p8\.hu|painelwebradiodigital\.awardspace\.info|sgwebdesigner\.free\.fr|yonelco\.com|pozdravizbeograda\.com|highclass\.atspace\.com|situluimihai\.3x\.ro|gatheredovertime\.com|imagebucket\.biz)$/i | table([@timestamp, ComputerName, UserName, ContextBaseFileName, ContextProcessId_decimal, DomainName, aid]) | sort(@timestamp, order=desc, limit=1000)
Looks for: Windows executable launches from UNC paths or drive letters commonly assigned outside the system volume. Accomplishes: exposes one propagation surface documented for Sality but remains a broad same-host correlation hunt, not proof of file infection.
// HUNT: Executable launch from non-system or UNC path // HYPOTHESIS: H03 // USE: hunt // MITRE: T1091, T1021.002 // CONF: medium // FP: high // COST: low // TIMEFRAME: 30d — bounded analyst review window // REQUIRES: ProcessRollup2 or SyntheticProcessRollup2; ImageFileName, CommandLine, ParentBaseFileName // FALSE POSITIVES: portable applications, installers, mapped drives, and approved software distribution // TUNING: exclude only signed owner-approved paths and retain same-host Q01 or integrity correlation // VALIDATION: STATIC-ONLY #event_simpleName = /^(ProcessRollup2|SyntheticProcessRollup2)$/ | test(@timestamp >= now() - 2592000000) | ImageFileName = /^(?:\\|[D-Z]:\\).+\.exe$/i | table([@timestamp, ComputerName, UserName, ParentBaseFileName, ImageFileName, CommandLine, TargetProcessId, aid]) | sort(@timestamp, order=desc, limit=1000)
Operationalization and IOA Candidates
Alert-candidate rows have complete design-only packages. No query was scheduled, no notification route was activated, and no IOA or prevention rule was created.
| Query | Use | Decision | Readiness | Rationale |
|---|---|---|---|---|
| Q01 | alert-candidate | alert-package | design-only | Tenant parsing, positive testing, and benign baseline are not recorded. |
| Q02 | hunt | hunt-only | design-only | Tenant parsing, positive testing, and benign baseline are not recorded. |
| Q03 | hunt | hunt-only | design-only | Tenant parsing, positive testing, and benign baseline are not recorded. |
Machine-Readable IOC Appendix
Exact current-run values are source tagged and expire for mandatory review on 2026-12-06; expiration is not evidence of safety.
type,value,action,severity,expiration,description,tags ipv4,188.166.101.148,detect,high,2026-12-06,detect and investigate residual infection,source:S01 domain,theunforgiven.p8.hu,detect,high,2026-12-06,historical hunt and enrichment,source:S01 domain,painelwebradiodigital.awardspace.info,detect,high,2026-12-06,historical hunt and enrichment,source:S01 domain,sgwebdesigner.free.fr,detect,high,2026-12-06,historical hunt and enrichment,source:S01 domain,yonelco.com,detect,high,2026-12-06,historical hunt and enrichment,source:S01 domain,pozdravizbeograda.com,detect,high,2026-12-06,historical hunt and enrichment,source:S01 domain,highclass.atspace.com,detect,high,2026-12-06,historical hunt and enrichment,source:S01 domain,situluimihai.3x.ro,detect,high,2026-12-06,historical hunt and enrichment,source:S01 domain,gatheredovertime.com,detect,high,2026-12-06,historical hunt and enrichment,source:S01 domain,imagebucket.biz,detect,high,2026-12-06,historical hunt and enrichment,source:S01
188.166.101.148 theunforgiven.p8.hu painelwebradiodigital.awardspace.info sgwebdesigner.free.fr yonelco.com pozdravizbeograda.com highclass.atspace.com situluimihai.3x.ro gatheredovertime.com imagebucket.biz
Current source provenance proves transcription, not maliciousness, ownership, or safe blocking. Corroborate every hit.
Hardening — Tiered and Deployable
- Quarantine corroborated infected hosts and restore executables from known-good media (M1040; CTRL01) — isolate only after Q01 or host evidence is verified; preserve memory and executable samples first deployable-design Verify: confirm restored system hashes and absence of unexplained Q01-Q03 hits Rollback: return network access only after business-owner and incident-commander approval Authority: NIST SP 800-83 Rev.1.
- Pilot Network Protection and controlled egress (M1037; CTRL02) — enable Audit mode for a representative pilot, review impact, then Block only under change control deployable-design Verify: export policy state and retain approved benign test evidence Rollback: restore the prior policy state through the same management channel Authority: Microsoft Network Protection guidance accessed 2026-09-06.
- Constrain execution from untrusted removable and network locations (M1038; CTRL03) — build an audit policy for unsigned or unapproved executables from removable and UNC paths before enforcement deployable-design Verify: retain policy XML, audit events, owner approvals, and compatibility results Rollback: deploy the prepared signed rollback policy or return the pilot to audit Authority: Microsoft App Control guidance accessed 2026-09-06.
- Maintain executable integrity and removable-media ownership (M1050; CTRL04) — assign owners to exceptions, remove unowned autorun paths, and recertify trusted executable baselines quarterly deployable-design Verify: sample ten exceptions and verify owner, signer, purpose, approval, and expiry Rollback: grant a time-bounded emergency exception under change control Authority: NIST SP 800-83 Rev.1.
Deployable playbook · PB01 · guarded pilot and rollback
- Export endpoint, egress, and application-control state
- preserve memory and suspicious executables
- apply isolation to a limited confirmed host set
- verify business-critical services and absence of new Sality signals
- expand only with incident authority
- rollback network or policy changes through the recorded management channel
- retain all logs, hashes, approvals, and recovery evidence.
Containment Runbook
| Phase | Trigger | Authority | Owner | Evidence | Recovery |
|---|---|---|---|---|---|
| 1. Validate and preserve | Q01 hit or corroborated Sality IOC | SOC lead | SOC analyst | raw rows, process/network context, memory and hashes | none; evidence capture is read-only |
| 2. Scope peers and propagation | confirmed residual infection | incident commander | endpoint responder | peer traffic, DNS, file and share activity | document benign explanation or continue |
| 3. Isolate affected endpoints | active infection or file mutation confirmed | incident commander plus service owner | endpoint operations | isolation time, exceptions, business impact | temporary access only under continuity plan |
| 4. Eradicate file infection | evidence preserved and scope stable | incident commander | endpoint engineering | rebuild or restoration record, known-good hashes | restore prior image only if integrity is proven |
| 5. Recover and re-hunt | known-good state restored | incident commander and system owner | SOC and endpoint engineering | fresh Q01-Q03 results and health checks | return service after no unexplained hits |
Preservation order: raw results, events, process tree, files and hashes, network/DNS, identity/session state, relevant policy, analyst notes and tool logs. Closure: known-good recovery, explained re-hunt results, and incident-commander plus system-owner approval.
Detection Coverage and Validation Evidence
Validation state: STATIC REVIEW PASSED only after the local gate suite completes. This is not Falcon parsing, canary success, schedule creation, or deployment evidence.
| Technique | Coverage | Query or handoff | Evidence | Limitation |
|---|---|---|---|---|
| T1095 | Static or design | Q01, Q02, Q03 | local structure, field, syntax, provenance, safety review | tenant parser, baseline, positive and benign tests absent |
| T1021.002 | Static or design | native and same-host correlation | local structure, field, syntax, provenance, safety review | tenant parser, baseline, positive and benign tests absent |
| T1091 | Static or design | native and same-host correlation | local structure, field, syntax, provenance, safety review | tenant parser, baseline, positive and benign tests absent |
| T1027.013 | Static or design | native and same-host correlation | local structure, field, syntax, provenance, safety review | tenant parser, baseline, positive and benign tests absent |
| T1105 | Static or design | native and same-host correlation | local structure, field, syntax, provenance, safety review | tenant parser, baseline, positive and benign tests absent |
Recorded evidence and next tests
- Every CQL card retains VALIDATION: STATIC-ONLY; no Falcon tenant was contacted.
- The offline tenant dry run checks extraction and profile readiness only.
- Next: parse the strongest query in the intended repository over one hour, verify fields, then run approved inert positive and 30-day benign tests.
Hunt Summary Ticket
TITLE: Sality hunt — v0.1 Draft SEVERITY: high — active malware behavior can enable propagation or follow-on compromise SCOPE: Windows Falcon endpoint, DNS, file, and network telemetry plus approved host pivots HYPOTHESIS: H01 alert-candidate — Post-disruption Sality lighthouse communication; H02 hunt — DNS lookup to final Sality URL-pack hosts; H03 hunt — Executable launch from network or non-system volume; H04 gap — Polymorphic file infection or memory-resident Sality keys QUERIES RUN: Q01 alert-candidate; Q02 hunt; Q03 hunt DO FIRST: Q01 over 30d FINDINGS: GAPS: tenant parsing, baseline, positive/benign tests, and external host semantics ACTIONS: SOC validates the strongest query; endpoint engineering preserves and scopes evidence OWNER: Security Operations / Endpoint Detection Engineering VERSION: v0.1 Draft · 2026-09-06 · STATIC REVIEW PASSED
Changelog
References
| ID | Publisher | Version/status | Accessed | Use | URL |
|---|---|---|---|---|---|
| S01 | CrowdStrike | successful sanitized technical extraction | 2026-09-06T11:06:41Z | C01, C02, C03, C04, C05, C06 | https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/ |
| S02 | U.S. Department of Justice | successful sanitized government release | 2026-09-06T11:06:41Z | C03, C06 | https://www.justice.gov/usao-cdca/pr/sality-malware-disrupted-international-cyber-takedown |
| S03 | Europol | successful sanitized government release | 2026-09-06T11:06:41Z | C02, C03 | https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades |
| S04 | Microsoft Learn | successful authoritative control summary | 2026-09-06T11:06:41Z | C07 | https://learn.microsoft.com/windows/security/application-security/application-control/windows-defender-application-control/wdac |
| S05 | Microsoft Learn | successful authoritative control summary | 2026-09-06T11:06:41Z | C08 | https://learn.microsoft.com/en-us/defender-endpoint/network-protection |
| S06 | NIST | successful authoritative guidance summary | 2026-09-06T11:06:41Z | C09 | https://csrc.nist.gov/pubs/sp/800/83/r1/final |