MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4d8ab6524f349bb970d16e8ce5a12cc559ed6cb26707301690bc8a2f93e3ae8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 10


Intelligence 10 IOCs YARA 4 File information Comments

SHA256 hash: d4d8ab6524f349bb970d16e8ce5a12cc559ed6cb26707301690bc8a2f93e3ae8
SHA3-384 hash: a2ee2de0f87528f4a68ce1ce474f42e87fb9b5d4022b3a366e51b76efeae3f3edd5e45c8b46f77783e96f5e94e471dbe
SHA1 hash: f253c1942f25c3c6a617832c34b99f6990d9df04
MD5 hash: b012ae8c6c7756c25a119889285ce999
humanhash: uniform-cup-west-butter
File name:d4d8ab6524f349bb970d16e8ce5a12cc559ed6cb26707301690bc8a2f93e3ae8
Download: download sample
Signature Prometei
File size:449'073 bytes
First seen:2026-05-26 18:49:24 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:Fs+/py5fM2l+M5F7TsJwtY1yvr+bT1psS+6T6NCj76tsdS:Fs6pyCC/Ya2hpi6T6N48
TLSH T15AA423B4F9219E9F6DD769B91B24C31DE182C172589D4C2313AE94A34F3D632AF2C816
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter c2hunter
Tags:elf Prometei wraith

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Manages services
Kills processes
Collects information on the CPU
Creating a file
Launching a process
Collects information on the OS
Changes access rights for a written file
Writes files to system directory
Writes files to system subdirectory
Deleting of the original file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
117
Number of processes launched:
29
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Persistence
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-05-26T16:28:00Z UTC
Last seen:
2026-05-27T00:15:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=4aafb9ee-1600-0000-c0f5-f874f60e0000 pid=3830 /usr/bin/sudo guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840 /tmp/sample.bin delete-file mprotect-exec write-file guuid=4aafb9ee-1600-0000-c0f5-f874f60e0000 pid=3830->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840 execve guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3905 /tmp/sample.bin guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3905 clone guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3906 /tmp/sample.bin guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3906 clone guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3927 /tmp/sample.bin guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3927 clone guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3928 /tmp/sample.bin guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3928 clone guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4107 /tmp/sample.bin guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4107 clone guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4108 /tmp/sample.bin guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4108 clone guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4394 /tmp/sample.bin guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4394 clone guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4395 /tmp/sample.bin guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4395 clone guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4630 /tmp/sample.bin guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4630 clone guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4632 /tmp/sample.bin guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4632 clone guuid=b290df0a-1800-0000-c0f5-f874d6120000 pid=4822 /usr/bin/dash guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=b290df0a-1800-0000-c0f5-f874d6120000 pid=4822 execve guuid=cc85e24c-1800-0000-c0f5-f874b0130000 pid=5040 /usr/bin/dash guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=cc85e24c-1800-0000-c0f5-f874b0130000 pid=5040 execve guuid=3a13806d-1800-0000-c0f5-f87430140000 pid=5168 /usr/bin/dash guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3840->guuid=3a13806d-1800-0000-c0f5-f87430140000 pid=5168 execve guuid=ff6d7c06-1700-0000-c0f5-f874430f0000 pid=3907 /usr/bin/dash guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3906->guuid=ff6d7c06-1700-0000-c0f5-f874430f0000 pid=3907 execve guuid=85edcd06-1700-0000-c0f5-f874450f0000 pid=3909 /usr/bin/pgrep guuid=ff6d7c06-1700-0000-c0f5-f874430f0000 pid=3907->guuid=85edcd06-1700-0000-c0f5-f874450f0000 pid=3909 execve guuid=cbbb2e0c-1700-0000-c0f5-f874590f0000 pid=3929 /usr/bin/dash guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=3928->guuid=cbbb2e0c-1700-0000-c0f5-f874590f0000 pid=3929 execve guuid=219d640c-1700-0000-c0f5-f8745b0f0000 pid=3931 /usr/bin/pgrep guuid=cbbb2e0c-1700-0000-c0f5-f874590f0000 pid=3929->guuid=219d640c-1700-0000-c0f5-f8745b0f0000 pid=3931 execve guuid=16cd8c4a-1700-0000-c0f5-f8740e100000 pid=4110 /usr/bin/dash guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4108->guuid=16cd8c4a-1700-0000-c0f5-f8740e100000 pid=4110 execve guuid=95b8df4a-1700-0000-c0f5-f8740f100000 pid=4111 /usr/sbin/killall5 guuid=16cd8c4a-1700-0000-c0f5-f8740e100000 pid=4110->guuid=95b8df4a-1700-0000-c0f5-f8740f100000 pid=4111 execve guuid=c11e9c8e-1700-0000-c0f5-f8742c110000 pid=4396 /usr/bin/dash guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4395->guuid=c11e9c8e-1700-0000-c0f5-f8742c110000 pid=4396 execve guuid=c7eac78e-1700-0000-c0f5-f8742e110000 pid=4398 /usr/bin/pgrep guuid=c11e9c8e-1700-0000-c0f5-f8742c110000 pid=4396->guuid=c7eac78e-1700-0000-c0f5-f8742e110000 pid=4398 execve guuid=8b33a2cc-1700-0000-c0f5-f87419120000 pid=4633 /usr/bin/dash guuid=ab4131f0-1600-0000-c0f5-f874000f0000 pid=4632->guuid=8b33a2cc-1700-0000-c0f5-f87419120000 pid=4633 execve guuid=73b00fcd-1700-0000-c0f5-f8741a120000 pid=4634 /usr/sbin/killall5 guuid=8b33a2cc-1700-0000-c0f5-f87419120000 pid=4633->guuid=73b00fcd-1700-0000-c0f5-f8741a120000 pid=4634 execve guuid=45113a0b-1800-0000-c0f5-f874d7120000 pid=4823 /usr/bin/systemctl guuid=b290df0a-1800-0000-c0f5-f874d6120000 pid=4822->guuid=45113a0b-1800-0000-c0f5-f874d7120000 pid=4823 execve guuid=33e90b4d-1800-0000-c0f5-f874b1130000 pid=5041 /usr/bin/systemctl guuid=cc85e24c-1800-0000-c0f5-f874b0130000 pid=5040->guuid=33e90b4d-1800-0000-c0f5-f874b1130000 pid=5041 execve guuid=318bad6d-1800-0000-c0f5-f87432140000 pid=5170 /usr/bin/systemctl guuid=3a13806d-1800-0000-c0f5-f87430140000 pid=5168->guuid=318bad6d-1800-0000-c0f5-f87432140000 pid=5170 execve guuid=2fdaba13-0000-0000-c0f5-f87401000000 pid=1 /usr/lib/systemd/systemd guuid=75e4d76e-1800-0000-c0f5-f87437140000 pid=5175 /usr/sbin/uplugplay mprotect-exec guuid=2fdaba13-0000-0000-c0f5-f87401000000 pid=1->guuid=75e4d76e-1800-0000-c0f5-f87437140000 pid=5175 execve guuid=1d4d6b77-1800-0000-c0f5-f8744c140000 pid=5196 /usr/sbin/uplugplay guuid=75e4d76e-1800-0000-c0f5-f87437140000 pid=5175->guuid=1d4d6b77-1800-0000-c0f5-f8744c140000 pid=5196 clone guuid=afd48677-1800-0000-c0f5-f8744d140000 pid=5197 /usr/bin/dash guuid=1d4d6b77-1800-0000-c0f5-f8744c140000 pid=5196->guuid=afd48677-1800-0000-c0f5-f8744d140000 pid=5197 execve guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199 /usr/sbin/uplugplay dns mprotect-exec net send-data write-config guuid=afd48677-1800-0000-c0f5-f8744d140000 pid=5197->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199 execve 72feda4e-8ff4-5eee-be80-abecb8d0eda9 103.176.111.176:80 guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->72feda4e-8ff4-5eee-be80-abecb8d0eda9 send: 953B 99a07b9c-a06a-5036-a75d-39daa574df85 255.255.255.255:53 guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->99a07b9c-a06a-5036-a75d-39daa574df85 send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5254 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5254 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5283 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5283 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5284 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5284 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5299 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5299 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5300 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5300 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5303 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5303 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5304 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5304 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5307 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5307 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5308 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5308 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5311 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5311 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5312 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5312 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5314 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5314 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5315 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5315 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5317 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5317 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5318 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5318 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5321 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5321 clone guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5322 /usr/sbin/uplugplay guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5199->guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5322 clone guuid=8880819e-1800-0000-c0f5-f874a5140000 pid=5285 /usr/bin/dash guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5284->guuid=8880819e-1800-0000-c0f5-f874a5140000 pid=5285 execve guuid=633eb79e-1800-0000-c0f5-f874a6140000 pid=5286 /usr/bin/hostnamectl guuid=8880819e-1800-0000-c0f5-f874a5140000 pid=5285->guuid=633eb79e-1800-0000-c0f5-f874a6140000 pid=5286 execve guuid=c54e3fb3-1800-0000-c0f5-f874b5140000 pid=5301 /usr/bin/dash guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5300->guuid=c54e3fb3-1800-0000-c0f5-f874b5140000 pid=5301 execve guuid=31c26bb3-1800-0000-c0f5-f874b6140000 pid=5302 /usr/bin/uptime guuid=c54e3fb3-1800-0000-c0f5-f874b5140000 pid=5301->guuid=31c26bb3-1800-0000-c0f5-f874b6140000 pid=5302 execve guuid=dd14bfb4-1800-0000-c0f5-f874b9140000 pid=5305 /usr/bin/dash guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5304->guuid=dd14bfb4-1800-0000-c0f5-f874b9140000 pid=5305 execve guuid=f4819eb5-1800-0000-c0f5-f874ba140000 pid=5306 /usr/bin/uname guuid=dd14bfb4-1800-0000-c0f5-f874b9140000 pid=5305->guuid=f4819eb5-1800-0000-c0f5-f874ba140000 pid=5306 execve guuid=e7bdf8b5-1800-0000-c0f5-f874bd140000 pid=5309 /usr/bin/dash guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5308->guuid=e7bdf8b5-1800-0000-c0f5-f874bd140000 pid=5309 execve guuid=af8324b6-1800-0000-c0f5-f874be140000 pid=5310 /usr/bin/hostnamectl guuid=e7bdf8b5-1800-0000-c0f5-f874bd140000 pid=5309->guuid=af8324b6-1800-0000-c0f5-f874be140000 pid=5310 execve guuid=5feda3b6-1800-0000-c0f5-f874c1140000 pid=5313 /usr/bin/dash send-data guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5312->guuid=5feda3b6-1800-0000-c0f5-f874c1140000 pid=5313 execve 5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 0.0.0.0:0 guuid=5feda3b6-1800-0000-c0f5-f874c1140000 pid=5313->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 28B guuid=8e6228b8-1800-0000-c0f5-f874c4140000 pid=5316 /usr/bin/dash send-data guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5315->guuid=8e6228b8-1800-0000-c0f5-f874c4140000 pid=5316 execve guuid=8e6228b8-1800-0000-c0f5-f874c4140000 pid=5316->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 28B guuid=2d7d42f6-1800-0000-c0f5-f874c7140000 pid=5319 /usr/bin/dash guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5318->guuid=2d7d42f6-1800-0000-c0f5-f874c7140000 pid=5319 execve guuid=c2437cf6-1800-0000-c0f5-f874c8140000 pid=5320 /usr/bin/uptime guuid=2d7d42f6-1800-0000-c0f5-f874c7140000 pid=5319->guuid=c2437cf6-1800-0000-c0f5-f874c8140000 pid=5320 execve guuid=fcb7a6f7-1800-0000-c0f5-f874cb140000 pid=5323 /usr/bin/dash guuid=ab5bac77-1800-0000-c0f5-f8744f140000 pid=5322->guuid=fcb7a6f7-1800-0000-c0f5-f874cb140000 pid=5323 execve guuid=0750e0f7-1800-0000-c0f5-f874cc140000 pid=5324 /usr/bin/uname guuid=fcb7a6f7-1800-0000-c0f5-f874cb140000 pid=5323->guuid=0750e0f7-1800-0000-c0f5-f874cc140000 pid=5324 execve
Threat name:
Linux.Trojan.Prometei
Status:
Malicious
First seen:
2026-05-26 18:50:55 UTC
File Type:
ELF64 Little (Exe)
AV detection:
19 of 37 (51.35%)
Threat level:
  5/5
Result
Malware family:
prometei_elf
Score:
  10/10
Tags:
family:prometei_elf botnet discovery linux miner persistence privilege_escalation upx
Behaviour
Reads runtime system information
Reads CPU attributes
UPX packed file
Enumerates running processes
Modifies systemd
Write file to user bin folder
Deletes itself
Modifies hosts file
Family: Prometei
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments