MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e4ce6007899a4e82918d396c51dce60f783c15e95bbf0dabac5fe78a134639bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 8


Intelligence 8 IOCs YARA 4 File information Comments

SHA256 hash: e4ce6007899a4e82918d396c51dce60f783c15e95bbf0dabac5fe78a134639bc
SHA3-384 hash: f20770639f2b669d099207198184e04a97863091a5e5f297cee06689e170e2c7d8d9ecd138150dcd03dd584174e9e64d
SHA1 hash: d12bd249fa482e8eab2d6c19d635ff2b1c416827
MD5 hash: ee4c71c272485e6f023d826906595b9d
humanhash: montana-crazy-wyoming-foxtrot
File name:e4ce6007899a4e82918d396c51dce60f783c15e95bbf0dabac5fe78a134639bc
Download: download sample
Signature Prometei
File size:449'052 bytes
First seen:2026-06-01 00:07:38 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:Fs+/py5fM2l+M5F7TsJwtY1yvr+bT1psS+6T6NCj76tsdC:Fs6pyCC/Ya2hpi6T6N4s
TLSH T1FFA423B4F9229E9F6DD769B91B24C31DE181C172589D4C2313AE94A34F3D632AF2C816
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter c2hunter
Tags:elf Prometei wraith

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Manages services
Kills processes
Collects information on the CPU
Creating a file
Collects information on the OS
Launching a process
Changes access rights for a written file
Writes files to system directory
Writes files to system subdirectory
Deleting of the original file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
packed upx
Status:
terminated
Behavior Graph:
%3 guuid=4939e2f9-1600-0000-adf6-9145190e0000 pid=3609 /usr/bin/sudo guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626 /tmp/sample.bin delete-file mprotect-exec write-file guuid=4939e2f9-1600-0000-adf6-9145190e0000 pid=3609->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626 execve guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3663 /tmp/sample.bin guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3663 clone guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3664 /tmp/sample.bin guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3664 clone guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3676 /tmp/sample.bin guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3676 clone guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3677 /tmp/sample.bin guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3677 clone guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3904 /tmp/sample.bin guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3904 clone guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3905 /tmp/sample.bin guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3905 clone guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=4121 /tmp/sample.bin guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=4121 clone guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=4122 /tmp/sample.bin guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=4122 clone guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=4351 /tmp/sample.bin guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=4351 clone guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=4352 /tmp/sample.bin guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=4352 clone guuid=fea37119-1800-0000-adf6-9145e9110000 pid=4585 /usr/bin/dash guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=fea37119-1800-0000-adf6-9145e9110000 pid=4585 execve guuid=62ab7c86-1800-0000-adf6-91450c130000 pid=4876 /usr/bin/dash guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=62ab7c86-1800-0000-adf6-91450c130000 pid=4876 execve guuid=e09ae0b2-1800-0000-adf6-914587130000 pid=4999 /usr/bin/dash guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3626->guuid=e09ae0b2-1800-0000-adf6-914587130000 pid=4999 execve guuid=40cdd716-1700-0000-adf6-9145510e0000 pid=3665 /usr/bin/dash guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3664->guuid=40cdd716-1700-0000-adf6-9145510e0000 pid=3665 execve guuid=ad6f1317-1700-0000-adf6-9145520e0000 pid=3666 /usr/bin/pgrep guuid=40cdd716-1700-0000-adf6-9145510e0000 pid=3665->guuid=ad6f1317-1700-0000-adf6-9145520e0000 pid=3666 execve guuid=e69c4d1c-1700-0000-adf6-91455e0e0000 pid=3678 /usr/bin/dash guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3677->guuid=e69c4d1c-1700-0000-adf6-91455e0e0000 pid=3678 execve guuid=d2b7c21c-1700-0000-adf6-9145620e0000 pid=3682 /usr/bin/pgrep guuid=e69c4d1c-1700-0000-adf6-91455e0e0000 pid=3678->guuid=d2b7c21c-1700-0000-adf6-9145620e0000 pid=3682 execve guuid=74dce35a-1700-0000-adf6-9145420f0000 pid=3906 /usr/bin/dash guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=3905->guuid=74dce35a-1700-0000-adf6-9145420f0000 pid=3906 execve guuid=f330175b-1700-0000-adf6-9145440f0000 pid=3908 /usr/sbin/killall5 guuid=74dce35a-1700-0000-adf6-9145420f0000 pid=3906->guuid=f330175b-1700-0000-adf6-9145440f0000 pid=3908 execve guuid=d5d56b9d-1700-0000-adf6-91451b100000 pid=4123 /usr/bin/dash guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=4122->guuid=d5d56b9d-1700-0000-adf6-91451b100000 pid=4123 execve guuid=647e999d-1700-0000-adf6-91451c100000 pid=4124 /usr/bin/pgrep guuid=d5d56b9d-1700-0000-adf6-91451b100000 pid=4123->guuid=647e999d-1700-0000-adf6-91451c100000 pid=4124 execve guuid=9d098bdb-1700-0000-adf6-914501110000 pid=4353 /usr/bin/dash guuid=7c641bfd-1600-0000-adf6-91452a0e0000 pid=4352->guuid=9d098bdb-1700-0000-adf6-914501110000 pid=4353 execve guuid=d2f1b6db-1700-0000-adf6-914505110000 pid=4357 /usr/sbin/killall5 guuid=9d098bdb-1700-0000-adf6-914501110000 pid=4353->guuid=d2f1b6db-1700-0000-adf6-914505110000 pid=4357 execve guuid=01d0ac19-1800-0000-adf6-9145ea110000 pid=4586 /usr/bin/systemctl guuid=fea37119-1800-0000-adf6-9145e9110000 pid=4585->guuid=01d0ac19-1800-0000-adf6-9145ea110000 pid=4586 execve guuid=959aca86-1800-0000-adf6-91450e130000 pid=4878 /usr/bin/systemctl guuid=62ab7c86-1800-0000-adf6-91450c130000 pid=4876->guuid=959aca86-1800-0000-adf6-91450e130000 pid=4878 execve guuid=f27b0eb3-1800-0000-adf6-914588130000 pid=5000 /usr/bin/systemctl guuid=e09ae0b2-1800-0000-adf6-914587130000 pid=4999->guuid=f27b0eb3-1800-0000-adf6-914588130000 pid=5000 execve guuid=2fdaba13-0000-0000-adf6-914501000000 pid=1 /usr/lib/systemd/systemd guuid=77c40ab5-1800-0000-adf6-91458d130000 pid=5005 /usr/sbin/uplugplay mprotect-exec guuid=2fdaba13-0000-0000-adf6-914501000000 pid=1->guuid=77c40ab5-1800-0000-adf6-91458d130000 pid=5005 execve guuid=316eb7c4-1800-0000-adf6-9145b8130000 pid=5048 /usr/sbin/uplugplay guuid=77c40ab5-1800-0000-adf6-91458d130000 pid=5005->guuid=316eb7c4-1800-0000-adf6-9145b8130000 pid=5048 clone guuid=ffc2d6c4-1800-0000-adf6-9145b9130000 pid=5049 /usr/bin/dash guuid=316eb7c4-1800-0000-adf6-9145b8130000 pid=5048->guuid=ffc2d6c4-1800-0000-adf6-9145b9130000 pid=5049 execve guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050 /usr/sbin/uplugplay dns mprotect-exec net send-data write-config guuid=ffc2d6c4-1800-0000-adf6-9145b9130000 pid=5049->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050 execve 72feda4e-8ff4-5eee-be80-abecb8d0eda9 103.176.111.176:80 guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->72feda4e-8ff4-5eee-be80-abecb8d0eda9 send: 985B 99a07b9c-a06a-5036-a75d-39daa574df85 255.255.255.255:53 guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->99a07b9c-a06a-5036-a75d-39daa574df85 send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5092 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5092 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5158 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5158 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5160 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5160 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5190 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5190 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5191 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5191 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5200 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5200 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5201 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5201 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5202 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5202 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5203 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5203 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5315 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5315 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5316 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5316 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5317 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5317 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5319 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5319 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5353 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5353 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5354 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5354 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5359 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5359 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5360 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5360 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5362 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5362 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5363 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5363 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5366 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5366 clone guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5367 /usr/sbin/uplugplay guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5050->guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5367 clone guuid=87afbdf0-1800-0000-adf6-914529140000 pid=5161 /usr/bin/dash guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5160->guuid=87afbdf0-1800-0000-adf6-914529140000 pid=5161 execve guuid=560df8f0-1800-0000-adf6-91452b140000 pid=5163 /usr/bin/hostnamectl guuid=87afbdf0-1800-0000-adf6-914529140000 pid=5161->guuid=560df8f0-1800-0000-adf6-91452b140000 pid=5163 execve guuid=9a127102-1900-0000-adf6-914548140000 pid=5192 /usr/bin/dash guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5191->guuid=9a127102-1900-0000-adf6-914548140000 pid=5192 execve guuid=22d4d702-1900-0000-adf6-91454a140000 pid=5194 /usr/bin/hostnamectl guuid=9a127102-1900-0000-adf6-914548140000 pid=5192->guuid=22d4d702-1900-0000-adf6-91454a140000 pid=5194 execve guuid=8e0dc905-1900-0000-adf6-914555140000 pid=5205 /usr/bin/dash send-data guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5201->guuid=8e0dc905-1900-0000-adf6-914555140000 pid=5205 execve guuid=f66c4d06-1900-0000-adf6-914557140000 pid=5207 /usr/bin/dash send-data guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5203->guuid=f66c4d06-1900-0000-adf6-914557140000 pid=5207 execve 5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 0.0.0.0:0 guuid=8e0dc905-1900-0000-adf6-914555140000 pid=5205->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 28B guuid=f66c4d06-1900-0000-adf6-914557140000 pid=5207->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 28B guuid=325a1d3e-1a00-0000-adf6-9145c6140000 pid=5318 /usr/bin/dash send-data guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5317->guuid=325a1d3e-1a00-0000-adf6-9145c6140000 pid=5318 execve guuid=325a1d3e-1a00-0000-adf6-9145c6140000 pid=5318->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 28B guuid=c3b8f83e-1a00-0000-adf6-9145c8140000 pid=5320 /usr/bin/dash send-data guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5319->guuid=c3b8f83e-1a00-0000-adf6-9145c8140000 pid=5320 execve guuid=c3b8f83e-1a00-0000-adf6-9145c8140000 pid=5320->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 28B guuid=ee9bef78-1b00-0000-adf6-9145eb140000 pid=5355 /usr/bin/dash send-data guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5354->guuid=ee9bef78-1b00-0000-adf6-9145eb140000 pid=5355 execve guuid=ee9bef78-1b00-0000-adf6-9145eb140000 pid=5355->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 28B guuid=cf6d8dd5-2200-0000-adf6-9145f1140000 pid=5361 /usr/bin/dash send-data guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5360->guuid=cf6d8dd5-2200-0000-adf6-9145f1140000 pid=5361 execve guuid=cf6d8dd5-2200-0000-adf6-9145f1140000 pid=5361->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 28B guuid=dedae415-2300-0000-adf6-9145f4140000 pid=5364 /usr/bin/dash guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5363->guuid=dedae415-2300-0000-adf6-9145f4140000 pid=5364 execve guuid=2a585216-2300-0000-adf6-9145f5140000 pid=5365 /usr/bin/uptime guuid=dedae415-2300-0000-adf6-9145f4140000 pid=5364->guuid=2a585216-2300-0000-adf6-9145f5140000 pid=5365 execve guuid=bd8fea18-2300-0000-adf6-9145f8140000 pid=5368 /usr/bin/dash guuid=278411c5-1800-0000-adf6-9145ba130000 pid=5367->guuid=bd8fea18-2300-0000-adf6-9145f8140000 pid=5368 execve guuid=99ec6719-2300-0000-adf6-9145f9140000 pid=5369 /usr/bin/uname guuid=bd8fea18-2300-0000-adf6-9145f8140000 pid=5368->guuid=99ec6719-2300-0000-adf6-9145f9140000 pid=5369 execve
Threat name:
Linux.Trojan.Prometei
Status:
Malicious
First seen:
2026-06-01 00:08:42 UTC
File Type:
ELF64 Little (Exe)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
prometei_elf
Score:
  10/10
Tags:
family:prometei_elf botnet discovery linux miner persistence privilege_escalation upx
Behaviour
Reads runtime system information
Reads CPU attributes
UPX packed file
Enumerates running processes
Modifies systemd
Write file to user bin folder
Deletes itself
Modifies hosts file
Family: Prometei
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments