MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ebc0dbc9238ad6f0cfecece14fb8d8180b5cc2eac93dc016ceefbd693e0815ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 1


Intelligence 1 IOCs YARA File information Comments

SHA256 hash: ebc0dbc9238ad6f0cfecece14fb8d8180b5cc2eac93dc016ceefbd693e0815ee
SHA3-384 hash: e7412c567d65fd1bbe1eaeb2aee80dd55e7b79bf517f63fb8f371bb1f317223fc4a32742788192dde5ad96ac6d38a42d
SHA1 hash: f6c7c9b8bc8447a1120e5101c2012d92e2c33d0d
MD5 hash: 5b8e66688962830f740f3a1fd1fdac53
humanhash: queen-bluebird-high-east
File name:ebc0dbc9238ad6f0cfecece14fb8d8180b5cc2eac93dc016ceefbd693e0815ee
Download: download sample
Signature Prometei
File size:31 bytes
First seen:2026-05-26 00:09:17 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:FZwURyWdcW6:FZwURyWdk
TLSH TNULL
Magika csv
Reporter c2hunter
Tags:Prometei sh wraith

Intelligence


File Origin
# of uploads :
1
# of downloads :
9
Origin country :
US US
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=df86c74a-2100-0000-fb19-475ec6090000 pid=2502 /usr/bin/sudo guuid=aeaf704d-2100-0000-fb19-475ece090000 pid=2510 /tmp/sample.bin guuid=df86c74a-2100-0000-fb19-475ec6090000 pid=2502->guuid=aeaf704d-2100-0000-fb19-475ece090000 pid=2510 execve
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments