MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1435b46d9f4089dc92b0bc156f8a2cadfefbebb361e725b42b416f5f0746f49. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 9


Intelligence 9 IOCs YARA 4 File information Comments

SHA256 hash: a1435b46d9f4089dc92b0bc156f8a2cadfefbebb361e725b42b416f5f0746f49
SHA3-384 hash: fe37b6187fb74f268413c39d902243da7d62bf08f1f031bb67aa14216fbc1f6bc6f00b507cdaa879eccd0869a5da9624
SHA1 hash: 7aa41d2f5b5ddf90d27a65e13dcd9560d0d36b12
MD5 hash: f4444c358e2be03f75b553bff7cc9980
humanhash: five-video-don-quiet
File name:a1435b46d9f4089dc92b0bc156f8a2cadfefbebb361e725b42b416f5f0746f49
Download: download sample
Signature Prometei
File size:449'088 bytes
First seen:2026-06-02 10:28:24 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:Fs+/py5fM2l+M5F7TsJwtY1yvr+bT1psS+6T6NCj76tsdH:Fs6pyCC/Ya2hpi6T6N45
TLSH T153A423B4F9219E9F6DD769B91B24C31DE182C172589D4C2313AE94A34F3D632AF2C816
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter c2hunter
Tags:elf Prometei wraith

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Collects information on the CPU
Changes access rights for a written file
Creating a file
Collects information on the OS
Kills processes
Launching a process
Manages services
Writes files to system directory
Writes files to system subdirectory
Deleting of the original file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-06-02T09:31:00Z UTC
Last seen:
2026-06-02T09:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=dfbd8857-1700-0000-63d2-de484a0f0000 pid=3914 /usr/bin/sudo guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930 /tmp/sample.bin delete-file mprotect-exec write-file guuid=dfbd8857-1700-0000-63d2-de484a0f0000 pid=3914->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930 execve guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3993 /tmp/sample.bin guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3993 clone guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3994 /tmp/sample.bin guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3994 clone guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4016 /tmp/sample.bin guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4016 clone guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4017 /tmp/sample.bin guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4017 clone guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4293 /tmp/sample.bin guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4293 clone guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4294 /tmp/sample.bin guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4294 clone guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4526 /tmp/sample.bin guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4526 clone guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4527 /tmp/sample.bin guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4527 clone guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4679 /tmp/sample.bin guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4679 clone guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4680 /tmp/sample.bin guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4680 clone guuid=be114a6f-1800-0000-63d2-de48f5120000 pid=4853 /usr/bin/dash guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=be114a6f-1800-0000-63d2-de48f5120000 pid=4853 execve guuid=064f31a9-1800-0000-63d2-de48c1130000 pid=5057 /usr/bin/dash guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=064f31a9-1800-0000-63d2-de48c1130000 pid=5057 execve guuid=7142f1d0-1800-0000-63d2-de4855140000 pid=5205 /usr/bin/dash guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3930->guuid=7142f1d0-1800-0000-63d2-de4855140000 pid=5205 execve guuid=bc0d026e-1700-0000-63d2-de489b0f0000 pid=3995 /usr/bin/dash guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=3994->guuid=bc0d026e-1700-0000-63d2-de489b0f0000 pid=3995 execve guuid=34af316e-1700-0000-63d2-de489d0f0000 pid=3997 /usr/bin/pgrep guuid=bc0d026e-1700-0000-63d2-de489b0f0000 pid=3995->guuid=34af316e-1700-0000-63d2-de489d0f0000 pid=3997 execve guuid=1f985e72-1700-0000-63d2-de48b20f0000 pid=4018 /usr/bin/dash guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4017->guuid=1f985e72-1700-0000-63d2-de48b20f0000 pid=4018 execve guuid=a1828d72-1700-0000-63d2-de48b30f0000 pid=4019 /usr/bin/pgrep guuid=1f985e72-1700-0000-63d2-de48b20f0000 pid=4018->guuid=a1828d72-1700-0000-63d2-de48b30f0000 pid=4019 execve guuid=e70cd9af-1700-0000-63d2-de48c7100000 pid=4295 /usr/bin/dash guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4294->guuid=e70cd9af-1700-0000-63d2-de48c7100000 pid=4295 execve guuid=bf1514b0-1700-0000-63d2-de48c8100000 pid=4296 /usr/sbin/killall5 guuid=e70cd9af-1700-0000-63d2-de48c7100000 pid=4295->guuid=bf1514b0-1700-0000-63d2-de48c8100000 pid=4296 execve guuid=4121cdf2-1700-0000-63d2-de48b1110000 pid=4529 /usr/bin/dash guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4527->guuid=4121cdf2-1700-0000-63d2-de48b1110000 pid=4529 execve guuid=e03a2af3-1700-0000-63d2-de48b3110000 pid=4531 /usr/bin/pgrep guuid=4121cdf2-1700-0000-63d2-de48b1110000 pid=4529->guuid=e03a2af3-1700-0000-63d2-de48b3110000 pid=4531 execve guuid=78f2cd30-1800-0000-63d2-de4849120000 pid=4681 /usr/bin/dash guuid=5cdf345a-1700-0000-63d2-de485a0f0000 pid=4680->guuid=78f2cd30-1800-0000-63d2-de4849120000 pid=4681 execve guuid=fab7ff30-1800-0000-63d2-de484a120000 pid=4682 /usr/sbin/killall5 guuid=78f2cd30-1800-0000-63d2-de4849120000 pid=4681->guuid=fab7ff30-1800-0000-63d2-de484a120000 pid=4682 execve guuid=81fc766f-1800-0000-63d2-de48f6120000 pid=4854 /usr/bin/systemctl guuid=be114a6f-1800-0000-63d2-de48f5120000 pid=4853->guuid=81fc766f-1800-0000-63d2-de48f6120000 pid=4854 execve guuid=edb158a9-1800-0000-63d2-de48c5130000 pid=5061 /usr/bin/systemctl guuid=064f31a9-1800-0000-63d2-de48c1130000 pid=5057->guuid=edb158a9-1800-0000-63d2-de48c5130000 pid=5061 execve guuid=4d1716d1-1800-0000-63d2-de4857140000 pid=5207 /usr/bin/systemctl guuid=7142f1d0-1800-0000-63d2-de4855140000 pid=5205->guuid=4d1716d1-1800-0000-63d2-de4857140000 pid=5207 execve guuid=2fdaba13-0000-0000-63d2-de4801000000 pid=1 /usr/lib/systemd/systemd guuid=53ed65d2-1800-0000-63d2-de485b140000 pid=5211 /usr/sbin/uplugplay mprotect-exec guuid=2fdaba13-0000-0000-63d2-de4801000000 pid=1->guuid=53ed65d2-1800-0000-63d2-de485b140000 pid=5211 execve guuid=2d33cfde-1800-0000-63d2-de4882140000 pid=5250 /usr/sbin/uplugplay guuid=53ed65d2-1800-0000-63d2-de485b140000 pid=5211->guuid=2d33cfde-1800-0000-63d2-de4882140000 pid=5250 clone guuid=af63c3df-1800-0000-63d2-de4889140000 pid=5257 /usr/bin/dash guuid=2d33cfde-1800-0000-63d2-de4882140000 pid=5250->guuid=af63c3df-1800-0000-63d2-de4889140000 pid=5257 execve guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259 /usr/sbin/uplugplay dns mprotect-exec net send-data write-config guuid=af63c3df-1800-0000-63d2-de4889140000 pid=5257->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259 execve 72feda4e-8ff4-5eee-be80-abecb8d0eda9 103.176.111.176:80 guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->72feda4e-8ff4-5eee-be80-abecb8d0eda9 send: 1077B 99a07b9c-a06a-5036-a75d-39daa574df85 255.255.255.255:53 guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->99a07b9c-a06a-5036-a75d-39daa574df85 send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5290 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5290 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5294 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5294 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5295 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5295 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5307 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5307 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5308 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5308 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5311 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5311 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5312 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5312 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5315 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5315 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5316 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5316 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5319 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5319 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5320 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5320 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5323 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5323 clone guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5324 /usr/sbin/uplugplay guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5259->guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5324 clone guuid=ebb6fc04-1900-0000-63d2-de48b0140000 pid=5296 /usr/bin/dash guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5295->guuid=ebb6fc04-1900-0000-63d2-de48b0140000 pid=5296 execve guuid=d8d74405-1900-0000-63d2-de48b1140000 pid=5297 /usr/bin/hostnamectl guuid=ebb6fc04-1900-0000-63d2-de48b0140000 pid=5296->guuid=d8d74405-1900-0000-63d2-de48b1140000 pid=5297 execve guuid=f1e3d512-1900-0000-63d2-de48bd140000 pid=5309 /usr/bin/dash guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5308->guuid=f1e3d512-1900-0000-63d2-de48bd140000 pid=5309 execve guuid=9c6f0b13-1900-0000-63d2-de48be140000 pid=5310 /usr/bin/uptime guuid=f1e3d512-1900-0000-63d2-de48bd140000 pid=5309->guuid=9c6f0b13-1900-0000-63d2-de48be140000 pid=5310 execve guuid=40d11b14-1900-0000-63d2-de48c1140000 pid=5313 /usr/bin/dash guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5312->guuid=40d11b14-1900-0000-63d2-de48c1140000 pid=5313 execve guuid=824d4a14-1900-0000-63d2-de48c2140000 pid=5314 /usr/bin/uname guuid=40d11b14-1900-0000-63d2-de48c1140000 pid=5313->guuid=824d4a14-1900-0000-63d2-de48c2140000 pid=5314 execve guuid=2a4a3a1d-1900-0000-63d2-de48c5140000 pid=5317 /usr/bin/dash guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5316->guuid=2a4a3a1d-1900-0000-63d2-de48c5140000 pid=5317 execve guuid=4a8d6c1d-1900-0000-63d2-de48c6140000 pid=5318 /usr/bin/hostnamectl guuid=2a4a3a1d-1900-0000-63d2-de48c5140000 pid=5317->guuid=4a8d6c1d-1900-0000-63d2-de48c6140000 pid=5318 execve guuid=5d07641f-1900-0000-63d2-de48c9140000 pid=5321 /usr/bin/dash guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5320->guuid=5d07641f-1900-0000-63d2-de48c9140000 pid=5321 execve guuid=97918e1f-1900-0000-63d2-de48ca140000 pid=5322 /usr/bin/uptime guuid=5d07641f-1900-0000-63d2-de48c9140000 pid=5321->guuid=97918e1f-1900-0000-63d2-de48ca140000 pid=5322 execve guuid=3734ad20-1900-0000-63d2-de48cd140000 pid=5325 /usr/bin/dash guuid=6663ffdf-1800-0000-63d2-de488b140000 pid=5324->guuid=3734ad20-1900-0000-63d2-de48cd140000 pid=5325 execve guuid=8853da20-1900-0000-63d2-de48ce140000 pid=5326 /usr/bin/uname guuid=3734ad20-1900-0000-63d2-de48cd140000 pid=5325->guuid=8853da20-1900-0000-63d2-de48ce140000 pid=5326 execve
Threat name:
Linux.Trojan.Prometei
Status:
Malicious
First seen:
2026-06-02 10:29:41 UTC
File Type:
ELF64 Little (Exe)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
prometei_elf
Score:
  10/10
Tags:
family:prometei_elf botnet discovery linux miner persistence privilege_escalation upx
Behaviour
Reads runtime system information
Reads CPU attributes
UPX packed file
Enumerates running processes
Modifies systemd
Write file to user bin folder
Deletes itself
Modifies hosts file
Family: Prometei
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments