MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b6e528faacf10c8d9b64acb9ae50d17abc0420f5140ec61630dbc031045aeb2a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 8


Intelligence 8 IOCs YARA 4 File information Comments

SHA256 hash: b6e528faacf10c8d9b64acb9ae50d17abc0420f5140ec61630dbc031045aeb2a
SHA3-384 hash: af85345a298807085b9ed6c8d9e83bf5972ac3d27dd6b15e18179031febec262f9f9234173544a4aedc189002ebc09ec
SHA1 hash: 163977e4ad3933ff74dc8ab76f41fb55ee68c365
MD5 hash: 0cb17cb0160028d94a9d4ccec6f20902
humanhash: high-salami-oregon-maryland
File name:b6e528faacf10c8d9b64acb9ae50d17abc0420f5140ec61630dbc031045aeb2a
Download: download sample
Signature Prometei
File size:449'078 bytes
First seen:2026-06-26 14:45:02 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:Fs+/py5fM2l+M5F7TsJwtY1yvr+bT1psS+6T6NCj76tsdX:Fs6pyCC/Ya2hpi6T6N4Z
TLSH T17EA423B4F9219E8F6DD76DB91B24831DE182C172589D4C2313AE94A34F3D632BF2C816
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter c2hunter
Tags:elf Prometei wraith

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Collects information on the OS
Changes access rights for a written file
Collects information on the CPU
Kills processes
Launching a process
Manages services
Writes files to system subdirectory
Writes files to system directory
Deleting of the original file
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
124
Number of processes launched:
29
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Persistence
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=de6b7753-1900-0000-4f4e-ac022d140000 pid=5165 /usr/bin/sudo guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166 /tmp/sample.bin delete-file mprotect-exec write-file guuid=de6b7753-1900-0000-4f4e-ac022d140000 pid=5165->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166 execve guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5167 /tmp/sample.bin guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5167 clone guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5168 /tmp/sample.bin guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5168 clone guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5171 /tmp/sample.bin guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5171 clone guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5172 /tmp/sample.bin guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5172 clone guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5181 /tmp/sample.bin guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5181 clone guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5182 /tmp/sample.bin guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5182 clone guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5186 /tmp/sample.bin guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5186 clone guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5187 /tmp/sample.bin guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5187 clone guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5190 /tmp/sample.bin guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5190 clone guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5191 /tmp/sample.bin guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5191 clone guuid=b85f647f-1a00-0000-4f4e-ac024a140000 pid=5194 /usr/bin/dash guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=b85f647f-1a00-0000-4f4e-ac024a140000 pid=5194 execve guuid=c9045ea8-1a00-0000-4f4e-ac0261140000 pid=5217 /usr/bin/dash guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=c9045ea8-1a00-0000-4f4e-ac0261140000 pid=5217 execve guuid=bbed23d5-1a00-0000-4f4e-ac0283140000 pid=5251 /usr/bin/dash guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5166->guuid=bbed23d5-1a00-0000-4f4e-ac0283140000 pid=5251 execve guuid=5c62246f-1900-0000-4f4e-ac0231140000 pid=5169 /usr/bin/dash guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5168->guuid=5c62246f-1900-0000-4f4e-ac0231140000 pid=5169 execve guuid=04bb8d6f-1900-0000-4f4e-ac0232140000 pid=5170 /usr/bin/pgrep guuid=5c62246f-1900-0000-4f4e-ac0231140000 pid=5169->guuid=04bb8d6f-1900-0000-4f4e-ac0232140000 pid=5170 execve guuid=47a51076-1900-0000-4f4e-ac0235140000 pid=5173 /usr/bin/dash guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5172->guuid=47a51076-1900-0000-4f4e-ac0235140000 pid=5173 execve guuid=7f8a4976-1900-0000-4f4e-ac0236140000 pid=5174 /usr/bin/pgrep guuid=47a51076-1900-0000-4f4e-ac0235140000 pid=5173->guuid=7f8a4976-1900-0000-4f4e-ac0236140000 pid=5174 execve guuid=cdc57fb4-1900-0000-4f4e-ac0240140000 pid=5184 /usr/bin/dash guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5182->guuid=cdc57fb4-1900-0000-4f4e-ac0240140000 pid=5184 execve guuid=2c8729b5-1900-0000-4f4e-ac0241140000 pid=5185 /usr/sbin/killall5 guuid=cdc57fb4-1900-0000-4f4e-ac0240140000 pid=5184->guuid=2c8729b5-1900-0000-4f4e-ac0241140000 pid=5185 execve guuid=628552f8-1900-0000-4f4e-ac0244140000 pid=5188 /usr/bin/dash guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5187->guuid=628552f8-1900-0000-4f4e-ac0244140000 pid=5188 execve guuid=5b54d4f8-1900-0000-4f4e-ac0245140000 pid=5189 /usr/bin/pgrep guuid=628552f8-1900-0000-4f4e-ac0244140000 pid=5188->guuid=5b54d4f8-1900-0000-4f4e-ac0245140000 pid=5189 execve guuid=0f0a883b-1a00-0000-4f4e-ac0248140000 pid=5192 /usr/bin/dash guuid=daa12156-1900-0000-4f4e-ac022e140000 pid=5191->guuid=0f0a883b-1a00-0000-4f4e-ac0248140000 pid=5192 execve guuid=9457e03f-1a00-0000-4f4e-ac0249140000 pid=5193 /usr/sbin/killall5 guuid=0f0a883b-1a00-0000-4f4e-ac0248140000 pid=5192->guuid=9457e03f-1a00-0000-4f4e-ac0249140000 pid=5193 execve guuid=f288977f-1a00-0000-4f4e-ac024b140000 pid=5195 /usr/bin/systemctl guuid=b85f647f-1a00-0000-4f4e-ac024a140000 pid=5194->guuid=f288977f-1a00-0000-4f4e-ac024b140000 pid=5195 execve guuid=392996a8-1a00-0000-4f4e-ac0262140000 pid=5218 /usr/bin/systemctl guuid=c9045ea8-1a00-0000-4f4e-ac0261140000 pid=5217->guuid=392996a8-1a00-0000-4f4e-ac0262140000 pid=5218 execve guuid=ed4b58d5-1a00-0000-4f4e-ac0284140000 pid=5252 /usr/bin/systemctl guuid=bbed23d5-1a00-0000-4f4e-ac0283140000 pid=5251->guuid=ed4b58d5-1a00-0000-4f4e-ac0284140000 pid=5252 execve guuid=2fdaba13-0000-0000-4f4e-ac0201000000 pid=1 /usr/lib/systemd/systemd guuid=41f9a9d6-1a00-0000-4f4e-ac0285140000 pid=5253 /usr/sbin/uplugplay mprotect-exec guuid=2fdaba13-0000-0000-4f4e-ac0201000000 pid=1->guuid=41f9a9d6-1a00-0000-4f4e-ac0285140000 pid=5253 execve guuid=7fbec2df-1a00-0000-4f4e-ac0287140000 pid=5255 /usr/sbin/uplugplay guuid=41f9a9d6-1a00-0000-4f4e-ac0285140000 pid=5253->guuid=7fbec2df-1a00-0000-4f4e-ac0287140000 pid=5255 clone guuid=fecdecdf-1a00-0000-4f4e-ac0288140000 pid=5256 /usr/bin/dash guuid=7fbec2df-1a00-0000-4f4e-ac0287140000 pid=5255->guuid=fecdecdf-1a00-0000-4f4e-ac0288140000 pid=5256 execve guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257 /usr/sbin/uplugplay dns mprotect-exec net send-data write-config guuid=fecdecdf-1a00-0000-4f4e-ac0288140000 pid=5256->guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257 execve 72feda4e-8ff4-5eee-be80-abecb8d0eda9 103.176.111.176:80 guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257->72feda4e-8ff4-5eee-be80-abecb8d0eda9 send: 78B 99a07b9c-a06a-5036-a75d-39daa574df85 255.255.255.255:53 guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257->99a07b9c-a06a-5036-a75d-39daa574df85 send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5258 /usr/sbin/uplugplay guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257->guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5258 clone guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5260 /usr/sbin/uplugplay guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257->guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5260 clone guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5261 /usr/sbin/uplugplay guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257->guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5261 clone guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5268 /usr/sbin/uplugplay guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257->guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5268 clone guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5269 /usr/sbin/uplugplay guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257->guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5269 clone guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5274 /usr/sbin/uplugplay guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257->guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5274 clone guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5275 /usr/sbin/uplugplay guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5257->guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5275 clone guuid=05871fe8-1a00-0000-4f4e-ac028e140000 pid=5262 /usr/bin/dash guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5261->guuid=05871fe8-1a00-0000-4f4e-ac028e140000 pid=5262 execve guuid=136551e8-1a00-0000-4f4e-ac028f140000 pid=5263 /usr/bin/hostnamectl guuid=05871fe8-1a00-0000-4f4e-ac028e140000 pid=5262->guuid=136551e8-1a00-0000-4f4e-ac028f140000 pid=5263 execve guuid=0b2b4bfd-1a00-0000-4f4e-ac0296140000 pid=5270 /usr/bin/dash guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5269->guuid=0b2b4bfd-1a00-0000-4f4e-ac0296140000 pid=5270 execve guuid=717b7afd-1a00-0000-4f4e-ac0298140000 pid=5272 /usr/bin/uptime guuid=0b2b4bfd-1a00-0000-4f4e-ac0296140000 pid=5270->guuid=717b7afd-1a00-0000-4f4e-ac0298140000 pid=5272 execve guuid=e8657afe-1a00-0000-4f4e-ac029c140000 pid=5276 /usr/bin/dash guuid=64cc34e0-1a00-0000-4f4e-ac0289140000 pid=5275->guuid=e8657afe-1a00-0000-4f4e-ac029c140000 pid=5276 execve guuid=6dc7a5fe-1a00-0000-4f4e-ac029d140000 pid=5277 /usr/bin/uname guuid=e8657afe-1a00-0000-4f4e-ac029c140000 pid=5276->guuid=6dc7a5fe-1a00-0000-4f4e-ac029d140000 pid=5277 execve
Threat name:
Linux.Trojan.Prometei
Status:
Malicious
First seen:
2026-06-26 15:24:44 UTC
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
prometei_elf
Score:
  10/10
Tags:
family:prometei_elf botnet discovery linux miner persistence privilege_escalation upx
Behaviour
Reads runtime system information
Reads CPU attributes
UPX packed file
Enumerates running processes
Modifies systemd
Write file to user bin folder
Deletes itself
Modifies hosts file
Family: Prometei
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments