🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 32bd9d38455f4f7a939fce66e53dcada8a488e42e28755f4cdf96125b80b9f8c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 32bd9d38455f4f7a939fce66e53dcada8a488e42e28755f4cdf96125b80b9f8c
SHA3-384 hash: d6870d8a7a9084faad5ab29a7c253da8cc70e4902262561a96b85e9367d649143880938a860a6cef3468835f8d7dd11f
SHA1 hash: 8e0cc3c457398ee9dcdb7c608dab4f9540b54c79
MD5 hash: 36a898a7d8e525b6b50fa578e4ea6ecd
humanhash: angel-juliet-skylark-spaghetti
File name:fa7e96d54bc86e34e16c8741944acc0f007c353cb7d9c8be00e7bf366e747e52.zip
Download: download sample
Signature Prometei
File size:441'293 bytes
First seen:2026-10-02 08:28:57 UTC
Last seen:2026-10-08 08:42:06 UTC
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: infected
ssdeep 6144:PKP9isubw91nKPd4rJi1M4S5bl3n39Dco4Xc5B7b6/fDinjJbCd:PK1isummQJi1M4OblChczCinjlM
TLSH T16A942308DDCD613888B722605463EE3DE6F662D437C78DDC702B629F765A48207ACE5E
Magika zip
Reporter DarkDataLabs
Tags:Prometei

Intelligence


File Origin
# of uploads :
7
# of downloads :
132
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:fa7e96d54bc86e34e16c8741944acc0f007c353cb7d9c8be00e7bf366e747e52
File size:449'086 bytes
SHA256 hash: fa7e96d54bc86e34e16c8741944acc0f007c353cb7d9c8be00e7bf366e747e52
MD5 hash: 47a8d7967144b71c1a53a52a066769b0
MIME type:application/x-executable
Signature Prometei
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
packed upx
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Elf Executable Executable Zip Archive
Result
Malware family:
prometei_elf
Score:
  10/10
Tags:
family:prometei_elf botnet discovery linux miner persistence privilege_escalation upx
Behaviour
Reads runtime system information
Reads CPU attributes
UPX packed file
Enumerates running processes
Modifies systemd
Write file to user bin folder
Deletes itself
Modifies the /etc/hosts DNS resolution file
Family: Prometei
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments