MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8a2b190db07c84a4e72b1137cadd6c63a0c4f7b77db1684b2059039254aa1645. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 11


Intelligence 11 IOCs YARA 29 File information Comments

SHA256 hash: 8a2b190db07c84a4e72b1137cadd6c63a0c4f7b77db1684b2059039254aa1645
SHA3-384 hash: 5a3daf369a664e3b53a5817be0f459bf6ff78539a642116626cd51954029b636c8e4f0f3a723b3388529b536ea911b75
SHA1 hash: 3e4e4f651a88527b9e152c14ce72bc85aa944c18
MD5 hash: a8b7a00cfe25549ae6b95ef1def07962
humanhash: happy-west-snake-finch
File name:c512cad695fc027f3d3df46159a1f1b43d7641c37d6ade44870c052e36496bae
Download: download sample
Signature Prometei
File size:4'276'056 bytes
First seen:2026-05-13 10:35:47 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 98304:hiN8UtZkTarCS81X+HI5nZzZEWp91OKLB4k7FG3fE3xZf:ZO0OKLB4k33b
TLSH T145167E6BB1B354BCC15BD03097AFC663A835B4F40131BD7B36809A352E72E605B69F62
telfhash t15a0285740fb278b17297da00b393e4346ebb1d1a51f834f4b41276d5ee85ac14cbb862
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf Prometei upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 c512cad695fc027f3d3df46159a1f1b43d7641c37d6ade44870c052e36496bae
File size (compressed) :1'771'244 bytes
File size (de-compressed) :4'276'056 bytes
Format:linux/amd64
Packed file: c512cad695fc027f3d3df46159a1f1b43d7641c37d6ade44870c052e36496bae

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
NL NL
Vendor Threat Intelligence
Malware configuration found for:
MetaSploit
Details
MetaSploit
an executed command
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 coinminer expand gcc lolbin metasploit overlay prometei
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
111
Number of processes launched:
8
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2024-06-04T13:11:00Z UTC
Last seen:
2026-05-14T21:54:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=70aef15d-1900-0000-1e5b-d05d650c0000 pid=3173 /usr/bin/sudo guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179 /tmp/sample.bin net guuid=70aef15d-1900-0000-1e5b-d05d650c0000 pid=3173->guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179 execve 5dcfce94-a769-5606-af4f-9b62baa1b531 10.0.2.201:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->5dcfce94-a769-5606-af4f-9b62baa1b531 con 983578c5-66ba-5d8e-9472-46cdb0770998 10.0.2.201:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->983578c5-66ba-5d8e-9472-46cdb0770998 con 72b1fc1f-5a5b-5940-b030-51428608cea2 10.0.2.201:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->72b1fc1f-5a5b-5940-b030-51428608cea2 con 570c71e0-db6a-5394-b145-6c54ce0b3019 10.0.2.201:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->570c71e0-db6a-5394-b145-6c54ce0b3019 con f5c5e9ad-e51e-5933-8c63-01ffb9f5e19c 10.0.2.117:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->f5c5e9ad-e51e-5933-8c63-01ffb9f5e19c con cc47f994-4e21-5ba0-af6a-56a05df80399 10.0.2.117:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->cc47f994-4e21-5ba0-af6a-56a05df80399 con beee456c-6f07-5a03-acb5-d48b92993aee 10.0.2.117:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->beee456c-6f07-5a03-acb5-d48b92993aee con d67067e1-15d5-5175-b11f-95b59ee13564 10.0.2.117:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->d67067e1-15d5-5175-b11f-95b59ee13564 con a0f1ab75-a64a-5976-a91e-dd28a82da165 10.0.2.143:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a0f1ab75-a64a-5976-a91e-dd28a82da165 con f6007d8b-ac7f-5e7f-95e3-c6a9018b6fad 10.0.2.143:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->f6007d8b-ac7f-5e7f-95e3-c6a9018b6fad con 2f485b89-a93f-5a15-af10-7d9bbf811951 10.0.2.143:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->2f485b89-a93f-5a15-af10-7d9bbf811951 con 3d0eb8a3-a059-5b05-91b7-e53519195fcb 10.0.2.143:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->3d0eb8a3-a059-5b05-91b7-e53519195fcb con e099e50d-c262-5561-a970-30fe0e4f93ed 10.0.2.12:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e099e50d-c262-5561-a970-30fe0e4f93ed con a0ab2892-b2f4-5513-a2bd-12caee0eccdf 10.0.2.12:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a0ab2892-b2f4-5513-a2bd-12caee0eccdf con c613df2b-4db8-51ba-8db8-ba18de711dbf 10.0.2.12:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->c613df2b-4db8-51ba-8db8-ba18de711dbf con 4ac4f779-b3b4-56fe-83ba-ca18a1aeaf51 10.0.2.12:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->4ac4f779-b3b4-56fe-83ba-ca18a1aeaf51 con a26a1525-9dd2-5bbb-a3e9-4efe158df5c5 10.0.2.4:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a26a1525-9dd2-5bbb-a3e9-4efe158df5c5 con 852e80da-7fea-58df-ae5a-261d9329462d 10.0.2.4:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->852e80da-7fea-58df-ae5a-261d9329462d con 873b101d-ab7a-51c3-89e6-9d8cee4ff4bc 10.0.2.4:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->873b101d-ab7a-51c3-89e6-9d8cee4ff4bc con b916ac39-c99b-5e21-a638-7926c36221b7 10.0.2.4:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->b916ac39-c99b-5e21-a638-7926c36221b7 con cfdf7732-3fa9-5948-b7fa-927c884120b8 10.0.2.132:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->cfdf7732-3fa9-5948-b7fa-927c884120b8 con b83d411b-acd0-5480-84ac-50af51ad03b6 10.0.2.132:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->b83d411b-acd0-5480-84ac-50af51ad03b6 con 4631a9be-e435-535f-902c-bfe2c8f044d7 10.0.2.132:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->4631a9be-e435-535f-902c-bfe2c8f044d7 con bf4020b1-d295-55b4-b208-635765245483 10.0.2.132:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->bf4020b1-d295-55b4-b208-635765245483 con 07d67210-fc9e-5910-9305-59cde384bc6a 10.0.2.61:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->07d67210-fc9e-5910-9305-59cde384bc6a con 96310885-7c8a-5d9d-aad4-3218f52b8da9 10.0.2.61:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->96310885-7c8a-5d9d-aad4-3218f52b8da9 con a04e7d2f-5f23-5ac2-8aa3-39d423a1e6fc 10.0.2.61:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a04e7d2f-5f23-5ac2-8aa3-39d423a1e6fc con 70784919-df84-50be-9f4e-627326847ea0 10.0.2.61:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->70784919-df84-50be-9f4e-627326847ea0 con 3c39fb98-cde8-5590-aa43-590307e11963 10.0.2.37:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->3c39fb98-cde8-5590-aa43-590307e11963 con 593e6bd4-16e0-5744-b8a1-e7ad15798a4a 10.0.2.37:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->593e6bd4-16e0-5744-b8a1-e7ad15798a4a con 38ef701b-a44c-5c92-b919-6ea8264e1879 10.0.2.37:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->38ef701b-a44c-5c92-b919-6ea8264e1879 con c75722e7-36f3-5411-8f8e-83cd5265252c 10.0.2.37:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->c75722e7-36f3-5411-8f8e-83cd5265252c con 4bf28b13-8933-5549-9a97-3cc9238fdcfa 10.0.2.34:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->4bf28b13-8933-5549-9a97-3cc9238fdcfa con e35b5fe8-5eb5-5bdc-ae46-0173d6c9251f 10.0.2.34:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e35b5fe8-5eb5-5bdc-ae46-0173d6c9251f con 52ff7862-8827-58b2-ac9a-5f1e91d392ce 10.0.2.34:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->52ff7862-8827-58b2-ac9a-5f1e91d392ce con 508c6231-211a-5202-81dd-2fe5c6ac37ae 10.0.2.34:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->508c6231-211a-5202-81dd-2fe5c6ac37ae con 052fc9a1-bd6f-51e5-894b-0c9d1a59031f 10.0.2.113:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->052fc9a1-bd6f-51e5-894b-0c9d1a59031f con e04aeb7b-4162-5804-9349-5ec384dc4d8b 10.0.2.113:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e04aeb7b-4162-5804-9349-5ec384dc4d8b con db3b7e50-1f07-581f-abf4-a5bc35ddd274 10.0.2.113:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->db3b7e50-1f07-581f-abf4-a5bc35ddd274 con bc8b0f13-9668-50cc-b311-77167cadbadd 10.0.2.113:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->bc8b0f13-9668-50cc-b311-77167cadbadd con e104b8fe-2977-5f28-8210-49579c5dc9a1 10.0.2.80:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e104b8fe-2977-5f28-8210-49579c5dc9a1 con 33f21359-919a-53bc-8fe6-c4611f37daab 10.0.2.80:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->33f21359-919a-53bc-8fe6-c4611f37daab con f7eb6467-e866-5205-815f-553887be2481 10.0.2.80:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->f7eb6467-e866-5205-815f-553887be2481 con c6b5351d-2f25-52b6-9b85-0d7244ce0c93 10.0.2.80:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->c6b5351d-2f25-52b6-9b85-0d7244ce0c93 con 7af53eeb-fb30-5335-92d5-1db6aa2e382d 10.0.2.127:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->7af53eeb-fb30-5335-92d5-1db6aa2e382d con b419511f-8006-5427-aede-418546e51b2f 10.0.2.127:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->b419511f-8006-5427-aede-418546e51b2f con 96d84990-0d7b-5455-800e-716d389ca250 10.0.2.127:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->96d84990-0d7b-5455-800e-716d389ca250 con e513e36b-5765-5c0c-a06b-e80997472850 10.0.2.127:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e513e36b-5765-5c0c-a06b-e80997472850 con 338afd30-9865-5385-8a1f-e1eecd25a4d8 10.0.2.160:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->338afd30-9865-5385-8a1f-e1eecd25a4d8 con 9d2c3467-c5f7-53d2-ac15-7fae6b41aab9 10.0.2.160:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->9d2c3467-c5f7-53d2-ac15-7fae6b41aab9 con 645f66f3-6b5a-5ea9-8e70-eeb2da652a6d 10.0.2.160:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->645f66f3-6b5a-5ea9-8e70-eeb2da652a6d con 2b220e34-e3f9-57e1-a7c7-ebdad965924e 10.0.2.160:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->2b220e34-e3f9-57e1-a7c7-ebdad965924e con a2a7e5dd-1154-5737-9bd2-621da72dbf7e 10.0.2.114:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a2a7e5dd-1154-5737-9bd2-621da72dbf7e con daa8a3a6-311e-56b6-bb6f-c07f31f89304 10.0.2.114:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->daa8a3a6-311e-56b6-bb6f-c07f31f89304 con ef1245bc-ecbe-5d59-a82d-938836979c1d 10.0.2.114:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->ef1245bc-ecbe-5d59-a82d-938836979c1d con e2e834b8-1ca9-5aa2-9f05-0b70bf884fbd 10.0.2.114:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e2e834b8-1ca9-5aa2-9f05-0b70bf884fbd con e06c11a9-d6c9-58cf-87a9-4bef2d04475f 10.0.2.110:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e06c11a9-d6c9-58cf-87a9-4bef2d04475f con 31eb398f-9c05-50a6-a8e2-88cd9c0f27a5 10.0.2.110:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->31eb398f-9c05-50a6-a8e2-88cd9c0f27a5 con d8db1263-8f85-5c6e-ba9c-f45c97718131 10.0.2.110:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->d8db1263-8f85-5c6e-ba9c-f45c97718131 con eea785a1-a562-5677-ad5b-d0b6150b6b6c 10.0.2.110:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->eea785a1-a562-5677-ad5b-d0b6150b6b6c con 50c2e9eb-91fb-5450-9eeb-8815922c1d49 10.0.2.5:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->50c2e9eb-91fb-5450-9eeb-8815922c1d49 con d9a5f9ed-f120-5d4d-9766-f93e216b0036 10.0.2.5:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->d9a5f9ed-f120-5d4d-9766-f93e216b0036 con 2eeafc02-30dd-515b-9154-ef855a93c813 10.0.2.5:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->2eeafc02-30dd-515b-9154-ef855a93c813 con 34d57514-36f6-5eb9-84c6-0c77a78c9883 10.0.2.5:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->34d57514-36f6-5eb9-84c6-0c77a78c9883 con d663f1c4-a23d-5af3-ac30-58deb2245fd0 10.0.2.104:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->d663f1c4-a23d-5af3-ac30-58deb2245fd0 con f24623a7-3754-593a-a338-cbad67293075 10.0.2.104:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->f24623a7-3754-593a-a338-cbad67293075 con 33d38012-89e7-516c-8916-9defed2ee8cf 10.0.2.104:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->33d38012-89e7-516c-8916-9defed2ee8cf con 25c33e48-27e6-5488-824c-0b102f4d1de9 10.0.2.104:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->25c33e48-27e6-5488-824c-0b102f4d1de9 con 57f99115-d750-5dee-a4e4-ee6a240ebba4 10.0.2.84:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->57f99115-d750-5dee-a4e4-ee6a240ebba4 con deb87d3d-fbfc-5222-9043-4f16e47f8716 10.0.2.84:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->deb87d3d-fbfc-5222-9043-4f16e47f8716 con d68e7d4f-ddc3-517d-a4cd-a8807aebf639 10.0.2.84:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->d68e7d4f-ddc3-517d-a4cd-a8807aebf639 con 4f95ec00-b81f-5603-9d56-97d0d1d02303 10.0.2.84:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->4f95ec00-b81f-5603-9d56-97d0d1d02303 con 0a38893a-e8fe-52f0-b4a6-59df6715f882 10.0.2.7:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->0a38893a-e8fe-52f0-b4a6-59df6715f882 con 8c3577e7-e821-5913-8ef4-3279e0ce9017 10.0.2.7:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->8c3577e7-e821-5913-8ef4-3279e0ce9017 con 1cf83d00-3234-5ea9-a764-a14eeaf9e554 10.0.2.7:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->1cf83d00-3234-5ea9-a764-a14eeaf9e554 con 3aca117b-cf22-5faa-b3f4-401e34afa96d 10.0.2.7:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->3aca117b-cf22-5faa-b3f4-401e34afa96d con e30cfa87-0c44-50ca-8190-7146e61d6a23 10.0.2.167:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e30cfa87-0c44-50ca-8190-7146e61d6a23 con 6b252424-044e-5649-a864-5d67d289787b 10.0.2.167:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->6b252424-044e-5649-a864-5d67d289787b con 82d832df-5b0c-5c7e-a7d0-821c411a6d7a 10.0.2.167:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->82d832df-5b0c-5c7e-a7d0-821c411a6d7a con 3f45af76-2724-5df6-842d-3ae792e92f11 10.0.2.167:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->3f45af76-2724-5df6-842d-3ae792e92f11 con 3dec6da8-5be8-5d00-be3a-0793058e7929 10.0.2.233:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->3dec6da8-5be8-5d00-be3a-0793058e7929 con 6d7eed12-441b-57f4-b7be-72fd719b34a5 10.0.2.233:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->6d7eed12-441b-57f4-b7be-72fd719b34a5 con 1bda5fb5-d34b-5255-b497-e65a25eceee8 10.0.2.233:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->1bda5fb5-d34b-5255-b497-e65a25eceee8 con c68b0c22-483a-593c-9f38-f59454c3e925 10.0.2.233:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->c68b0c22-483a-593c-9f38-f59454c3e925 con edbaefe7-acae-5142-8d8f-83af657d5dcf 10.0.2.247:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->edbaefe7-acae-5142-8d8f-83af657d5dcf con a8d3d64f-72aa-56ca-a0b3-dfba2812fc03 10.0.2.247:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a8d3d64f-72aa-56ca-a0b3-dfba2812fc03 con bed43a8a-54b4-5432-ab22-92d12da3eab8 10.0.2.247:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->bed43a8a-54b4-5432-ab22-92d12da3eab8 con 7c46418e-cc3b-5717-8138-1c794ec1cf5b 10.0.2.247:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->7c46418e-cc3b-5717-8138-1c794ec1cf5b con 07340580-a9a3-58e8-8fbc-e2b056561d27 10.0.2.128:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->07340580-a9a3-58e8-8fbc-e2b056561d27 con 28760c2e-3ae9-5001-a6f1-2d3369cd1ea0 10.0.2.128:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->28760c2e-3ae9-5001-a6f1-2d3369cd1ea0 con f529807f-e334-5748-9ce4-9d69d9dc02b5 10.0.2.128:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->f529807f-e334-5748-9ce4-9d69d9dc02b5 con 5639f3c3-89be-511e-b852-ec945d53e0ca 10.0.2.128:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->5639f3c3-89be-511e-b852-ec945d53e0ca con 76ca06c9-03d3-5f78-af3c-4cac66775761 10.0.2.203:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->76ca06c9-03d3-5f78-af3c-4cac66775761 con 387c0e73-586a-51b6-a76f-a3ded84a8a01 10.0.2.203:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->387c0e73-586a-51b6-a76f-a3ded84a8a01 con 76c692a1-b1ac-53bc-8b57-7eef186e385a 10.0.2.203:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->76c692a1-b1ac-53bc-8b57-7eef186e385a con 07143ad8-0632-5c59-af5c-7c1446eb44ff 10.0.2.203:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->07143ad8-0632-5c59-af5c-7c1446eb44ff con 51163e84-6072-56c4-b2f7-1927e4273cd7 10.0.2.17:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->51163e84-6072-56c4-b2f7-1927e4273cd7 con 184fa1b8-f488-50bc-9cae-2edf7f222bfa 10.0.2.17:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->184fa1b8-f488-50bc-9cae-2edf7f222bfa con 3f636370-bb4c-5fae-86cc-2fd067dbf3b8 10.0.2.17:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->3f636370-bb4c-5fae-86cc-2fd067dbf3b8 con 8e1b6419-714f-5329-8ff1-83f69dc0d19b 10.0.2.17:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->8e1b6419-714f-5329-8ff1-83f69dc0d19b con 07d4f401-8e4f-5f65-940d-7c306c310e58 10.0.2.151:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->07d4f401-8e4f-5f65-940d-7c306c310e58 con 663d3c0f-239c-5ae4-9ff8-434038d0ea8c 10.0.2.151:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->663d3c0f-239c-5ae4-9ff8-434038d0ea8c con 0819ce4e-ebf3-5770-8005-5da255f90737 10.0.2.151:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->0819ce4e-ebf3-5770-8005-5da255f90737 con 79bd9f96-0ee9-58b8-875d-88c932fb0f06 10.0.2.151:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->79bd9f96-0ee9-58b8-875d-88c932fb0f06 con 421a5841-6d31-59cc-9f19-125bf2a0bf91 10.0.2.13:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->421a5841-6d31-59cc-9f19-125bf2a0bf91 con b9c05c87-b8e9-5f5d-b371-69c59c94fa41 10.0.2.13:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->b9c05c87-b8e9-5f5d-b371-69c59c94fa41 con a315db70-8a33-56a9-b636-8a3eaebc21bd 10.0.2.13:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a315db70-8a33-56a9-b636-8a3eaebc21bd con 35679ca6-fcdd-5600-9a45-a6906076cf72 10.0.2.13:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->35679ca6-fcdd-5600-9a45-a6906076cf72 con 42dd80d3-b395-5e6f-b4ee-4bdf8181826d 10.0.2.136:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->42dd80d3-b395-5e6f-b4ee-4bdf8181826d con 929b1f34-3663-5399-861a-a5971c768b7f 10.0.2.136:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->929b1f34-3663-5399-861a-a5971c768b7f con efb0290c-4ade-5d29-85f6-37861e862ddd 10.0.2.136:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->efb0290c-4ade-5d29-85f6-37861e862ddd con 9f5de61e-bbde-583e-946c-62f277e5babe 10.0.2.136:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->9f5de61e-bbde-583e-946c-62f277e5babe con d34af35c-98ea-57f5-bdfe-6510c377923e 10.0.2.105:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->d34af35c-98ea-57f5-bdfe-6510c377923e con 6ec122ee-d4b1-5f1a-bbff-56ec98fbfb69 10.0.2.105:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->6ec122ee-d4b1-5f1a-bbff-56ec98fbfb69 con b8bc7bf0-6322-5435-93d8-e2da8a4c4d71 10.0.2.105:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->b8bc7bf0-6322-5435-93d8-e2da8a4c4d71 con 1b144cfa-ecb6-574e-a702-5deb4779df4f 10.0.2.105:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->1b144cfa-ecb6-574e-a702-5deb4779df4f con a7de47b8-f235-5768-896b-1d579e4c0d29 10.0.2.238:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a7de47b8-f235-5768-896b-1d579e4c0d29 con e3d2197a-db82-5230-9a37-25b114391f92 10.0.2.238:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e3d2197a-db82-5230-9a37-25b114391f92 con 86b3cb90-017f-57be-89a2-4e61e8013221 10.0.2.238:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->86b3cb90-017f-57be-89a2-4e61e8013221 con 53d2d07a-07df-5fd4-b2a7-93a3dae42dc2 10.0.2.238:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->53d2d07a-07df-5fd4-b2a7-93a3dae42dc2 con 6a067772-35cb-5337-b266-ac354235ebcc 10.0.2.106:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->6a067772-35cb-5337-b266-ac354235ebcc con 98f33a1d-cab5-59e3-b697-ffff9c5a9c93 10.0.2.106:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->98f33a1d-cab5-59e3-b697-ffff9c5a9c93 con c40f1a1b-1d7e-5402-8953-75cd977950b7 10.0.2.106:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->c40f1a1b-1d7e-5402-8953-75cd977950b7 con c5ac652c-167f-5e93-90a1-0ea22c98553f 10.0.2.106:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->c5ac652c-167f-5e93-90a1-0ea22c98553f con 3e154f6d-c8ad-5685-9976-42941dacefd4 10.0.2.44:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->3e154f6d-c8ad-5685-9976-42941dacefd4 con 396f7dab-c1b0-5593-80e0-dcf4d7de30fe 10.0.2.44:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->396f7dab-c1b0-5593-80e0-dcf4d7de30fe con efcf5ce1-02fa-5f41-a0e0-d5e6b0469102 10.0.2.44:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->efcf5ce1-02fa-5f41-a0e0-d5e6b0469102 con 440fe3a9-1a8c-555c-a767-bce5a2d1cb21 10.0.2.44:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->440fe3a9-1a8c-555c-a767-bce5a2d1cb21 con 008b3954-6bd4-5ac4-adde-32b4921074cf 10.0.2.92:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->008b3954-6bd4-5ac4-adde-32b4921074cf con e6b1ea6e-5f48-54c7-8c33-4ecef89ead71 10.0.2.92:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e6b1ea6e-5f48-54c7-8c33-4ecef89ead71 con f624398e-0d58-5578-aa62-3551ec812023 10.0.2.92:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->f624398e-0d58-5578-aa62-3551ec812023 con 2b1b3707-b407-5188-8341-740b0d5b38f0 10.0.2.92:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->2b1b3707-b407-5188-8341-740b0d5b38f0 con 9fdf842b-f024-5771-b76d-4ef8b66c6fb0 10.0.2.248:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->9fdf842b-f024-5771-b76d-4ef8b66c6fb0 con 4a479173-6948-5a18-a9e7-4a1442c51906 10.0.2.248:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->4a479173-6948-5a18-a9e7-4a1442c51906 con a8b194bd-d0da-50a5-889f-34f4840e36ab 10.0.2.248:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a8b194bd-d0da-50a5-889f-34f4840e36ab con 1303b1e0-adf9-588d-9a94-77d1075901d0 10.0.2.248:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->1303b1e0-adf9-588d-9a94-77d1075901d0 con b22f4067-d8c3-5799-91e8-36aec6cb0348 10.0.2.55:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->b22f4067-d8c3-5799-91e8-36aec6cb0348 con ea2ec4c8-42e2-57bf-9973-56de44099801 10.0.2.55:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->ea2ec4c8-42e2-57bf-9973-56de44099801 con 5b0cdcd6-8af3-547c-9a5b-5ed63aca3eff 10.0.2.55:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->5b0cdcd6-8af3-547c-9a5b-5ed63aca3eff con ddb13d6a-2ad0-5437-9480-01202ce69162 10.0.2.55:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->ddb13d6a-2ad0-5437-9480-01202ce69162 con a7f529bc-7fc3-5550-815c-8345a7f3b8c4 10.0.2.96:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a7f529bc-7fc3-5550-815c-8345a7f3b8c4 con 1f788acd-d935-565e-a061-a925daa0672b 10.0.2.96:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->1f788acd-d935-565e-a061-a925daa0672b con e8778b18-35db-52e6-bdc2-4e28433888e0 10.0.2.96:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e8778b18-35db-52e6-bdc2-4e28433888e0 con a9a7439f-ecd3-5e6c-93d2-2c5d9d60f6c8 10.0.2.96:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a9a7439f-ecd3-5e6c-93d2-2c5d9d60f6c8 con d2a1aa21-709b-5612-b878-51004c8666c3 10.0.2.118:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->d2a1aa21-709b-5612-b878-51004c8666c3 con edf74ac3-8cfd-5476-a401-cbe1a948b7f9 10.0.2.118:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->edf74ac3-8cfd-5476-a401-cbe1a948b7f9 con 8374969d-d2ce-5e67-9201-dcec4b18f345 10.0.2.118:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->8374969d-d2ce-5e67-9201-dcec4b18f345 con a6ebef30-c94f-59f4-9dc4-a07eda07084b 10.0.2.118:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a6ebef30-c94f-59f4-9dc4-a07eda07084b con 98363852-e796-56fd-a6c3-3bdfea57699c 10.0.2.116:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->98363852-e796-56fd-a6c3-3bdfea57699c con ad70eaae-40b4-5808-946c-0ee05ef0f626 10.0.2.116:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->ad70eaae-40b4-5808-946c-0ee05ef0f626 con 00286612-d7e5-58a5-98ad-529a83accb32 10.0.2.116:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->00286612-d7e5-58a5-98ad-529a83accb32 con 092d7697-a6e0-5f08-9e29-8e9b0bc01eac 10.0.2.116:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->092d7697-a6e0-5f08-9e29-8e9b0bc01eac con 0164e355-15a1-5e42-a8a4-3ed11f50496b 10.0.2.133:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->0164e355-15a1-5e42-a8a4-3ed11f50496b con e9431570-855d-5c03-a0c9-b900e3322d8f 10.0.2.133:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->e9431570-855d-5c03-a0c9-b900e3322d8f con a14834cb-1104-5230-8d8c-a76294d4f7e8 10.0.2.133:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->a14834cb-1104-5230-8d8c-a76294d4f7e8 con 2d851e1c-0710-5a8a-9043-738e82203782 10.0.2.133:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->2d851e1c-0710-5a8a-9043-738e82203782 con 37e326a7-8300-5eac-a081-8a2221acba07 10.0.2.152:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->37e326a7-8300-5eac-a081-8a2221acba07 con 207c23e1-c9d4-564e-b9f3-34bd018861e2 10.0.2.152:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->207c23e1-c9d4-564e-b9f3-34bd018861e2 con d576447a-6147-5dcc-8870-9511643230e2 10.0.2.152:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->d576447a-6147-5dcc-8870-9511643230e2 con d19955b5-7fa4-5457-be4d-8cf7c1a34ffb 10.0.2.152:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->d19955b5-7fa4-5457-be4d-8cf7c1a34ffb con 33d6ecb1-191e-5512-a599-71dc0b3cf48b 10.0.2.228:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->33d6ecb1-191e-5512-a599-71dc0b3cf48b con 91e05beb-46ad-5eaf-ab6d-b28cd478aa43 10.0.2.228:5985 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->91e05beb-46ad-5eaf-ab6d-b28cd478aa43 con 599a96cb-e27c-5371-a667-cde64c94ec68 10.0.2.228:22 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->599a96cb-e27c-5371-a667-cde64c94ec68 con bc9d8226-a086-5b7e-ac30-06c27c1ba648 10.0.2.228:6379 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->bc9d8226-a086-5b7e-ac30-06c27c1ba648 con ef7c893e-1cda-5c16-828e-5c9eb0eec5f9 10.0.2.204:445 guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->ef7c893e-1cda-5c16-828e-5c9eb0eec5f9 con guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3192 /tmp/sample.bin guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3192 clone guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3193 /tmp/sample.bin guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3193 clone guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3250 /tmp/sample.bin guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3250 clone guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3251 /tmp/sample.bin guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3251 clone guuid=f376d5e4-1900-0000-1e5b-d05d0d0d0000 pid=3341 /usr/bin/dash guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3179->guuid=f376d5e4-1900-0000-1e5b-d05d0d0d0000 pid=3341 execve guuid=a41ec367-1900-0000-1e5b-d05d7a0c0000 pid=3194 /usr/bin/dash guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3193->guuid=a41ec367-1900-0000-1e5b-d05d7a0c0000 pid=3194 execve guuid=55f1f767-1900-0000-1e5b-d05d7c0c0000 pid=3196 /usr/bin/pgrep guuid=a41ec367-1900-0000-1e5b-d05d7a0c0000 pid=3194->guuid=55f1f767-1900-0000-1e5b-d05d7c0c0000 pid=3196 execve guuid=619f6ba6-1900-0000-1e5b-d05db40c0000 pid=3252 /usr/bin/dash guuid=f51bfd60-1900-0000-1e5b-d05d6b0c0000 pid=3251->guuid=619f6ba6-1900-0000-1e5b-d05db40c0000 pid=3252 execve guuid=345caaa6-1900-0000-1e5b-d05db50c0000 pid=3253 /usr/sbin/killall5 guuid=619f6ba6-1900-0000-1e5b-d05db40c0000 pid=3252->guuid=345caaa6-1900-0000-1e5b-d05db50c0000 pid=3253 execve guuid=79f135e5-1900-0000-1e5b-d05d0e0d0000 pid=3342 /usr/bin/rm guuid=f376d5e4-1900-0000-1e5b-d05d0d0d0000 pid=3341->guuid=79f135e5-1900-0000-1e5b-d05d0e0d0000 pid=3342 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Trojan.Kaiji
Status:
Malicious
First seen:
2023-08-08 22:32:07 UTC
File Type:
ELF64 Little (Exe)
Extracted files:
1
AV detection:
23 of 38 (60.53%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Reads CPU attributes
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:Linux_Hacktool_Flooder_1a4eb229
Author:Elastic Security
Rule name:Linux_Hacktool_Flooder_f454ec10
Author:Elastic Security
Reference:0297e1ad6e180af85256a175183102776212d324a2ce0c4f32e8a44a2e2e9dad
Rule name:mal_metasploit_shellcode_windows_powershell_tcp
Author:Maxime THIEBAUT (@0xThiebaut)
Description:Detects Metasploit import-hashes from the windows/powershell_bind_tcp and windows/powershell_reverse_tcp payloads
Reference:https://blog.nviso.eu/2021/09/02/anatomy-and-disruption-of-metasploit-shellcode/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:Prometei_Main
Author:@bartblaze
Description:Identifies Prometei botnet main modules.
Reference:https://malpedia.caad.fkie.fraunhofer.de/details/win.prometei
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants
Rule name:Windows_Trojan_Metasploit_7bc0f998
Description:Identifies the API address lookup function leverage by metasploit shellcode
Rule name:Windows_Trojan_Metasploit_7bc0f998
Author:Elastic Security
Description:Identifies the API address lookup function leverage by metasploit shellcode
Rule name:Windows_Trojan_Metasploit_c9773203
Description:Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.
Reference:https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm
Rule name:Windows_Trojan_Metasploit_c9773203
Author:Elastic Security
Description:Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.
Reference:https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm
Rule name:Windows_Trojan_Metasploit_f7f826b4
Author:Elastic Security
Description:Identifies metasploit kernel->user shellcode. Likely used in ETERNALBLUE and BlueKeep exploits.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Prometei

elf 8a2b190db07c84a4e72b1137cadd6c63a0c4f7b77db1684b2059039254aa1645

(this sample)

Comments