MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef00389e3fb080dc811a7b0793ca481294191eac1d57fcc2eacf1af544c28a74. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 10


Intelligence 10 IOCs YARA 4 File information Comments

SHA256 hash: ef00389e3fb080dc811a7b0793ca481294191eac1d57fcc2eacf1af544c28a74
SHA3-384 hash: 95a1a53857a2e1040bea63c15542988b5c70d67c0b3e663b4a559711a1cad7fb6b2103526873182322b1c8d0f8c8a727
SHA1 hash: 2e063f00196cefaf71300ba952adb77a500f3cf9
MD5 hash: 6e5112cdded01445a69c1cf7342537e8
humanhash: nevada-two-football-potato
File name:ef00389e3fb080dc811a7b0793ca481294191eac1d57fcc2eacf1af544c28a74
Download: download sample
Signature Prometei
File size:449'078 bytes
First seen:2026-07-02 13:25:27 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:Fs+/py5fM2l+M5F7TsJwtY1yvr+bT1psS+6T6NCj76tsde:Fs6pyCC/Ya2hpi6T6N4I
TLSH T1A5A423B4F9219E9F6DD769B91B24831DE182C172589D4C2313AE94E34F3D632AF2CC16
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter c2hunter
Tags:elf Prometei wraith

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Collects information on the OS
Changes access rights for a written file
Collects information on the CPU
Kills processes
Launching a process
Manages services
Writes files to system subdirectory
Writes files to system directory
Deleting of the original file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
137
Number of processes launched:
85
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Persistence
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-07-02T14:04:00Z UTC
Last seen:
2026-07-03T19:49:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=7a4afc50-1900-0000-f303-47e42d140000 pid=5165 /usr/bin/sudo guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166 /tmp/sample.bin delete-file mprotect-exec write-file guuid=7a4afc50-1900-0000-f303-47e42d140000 pid=5165->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166 execve guuid=3238db52-1900-0000-f303-47e42e140000 pid=5167 /tmp/sample.bin guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5167 clone guuid=3238db52-1900-0000-f303-47e42e140000 pid=5168 /tmp/sample.bin guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5168 clone guuid=3238db52-1900-0000-f303-47e42e140000 pid=5171 /tmp/sample.bin guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5171 clone guuid=3238db52-1900-0000-f303-47e42e140000 pid=5172 /tmp/sample.bin guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5172 clone guuid=3238db52-1900-0000-f303-47e42e140000 pid=5175 /tmp/sample.bin guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5175 clone guuid=3238db52-1900-0000-f303-47e42e140000 pid=5176 /tmp/sample.bin guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5176 clone guuid=3238db52-1900-0000-f303-47e42e140000 pid=5186 /tmp/sample.bin guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5186 clone guuid=3238db52-1900-0000-f303-47e42e140000 pid=5187 /tmp/sample.bin guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5187 clone guuid=3238db52-1900-0000-f303-47e42e140000 pid=5190 /tmp/sample.bin guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5190 clone guuid=3238db52-1900-0000-f303-47e42e140000 pid=5191 /tmp/sample.bin guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=3238db52-1900-0000-f303-47e42e140000 pid=5191 clone guuid=201a2d86-1a00-0000-f303-47e44a140000 pid=5194 /usr/bin/dash guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=201a2d86-1a00-0000-f303-47e44a140000 pid=5194 execve guuid=2c141ec7-1a00-0000-f303-47e460140000 pid=5216 /usr/bin/dash guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=2c141ec7-1a00-0000-f303-47e460140000 pid=5216 execve guuid=dc3f400e-1b00-0000-f303-47e47d140000 pid=5245 /usr/bin/dash guuid=3238db52-1900-0000-f303-47e42e140000 pid=5166->guuid=dc3f400e-1b00-0000-f303-47e47d140000 pid=5245 execve guuid=8ef7cc6a-1900-0000-f303-47e431140000 pid=5169 /usr/bin/dash guuid=3238db52-1900-0000-f303-47e42e140000 pid=5168->guuid=8ef7cc6a-1900-0000-f303-47e431140000 pid=5169 execve guuid=203f2b6b-1900-0000-f303-47e432140000 pid=5170 /usr/bin/pgrep guuid=8ef7cc6a-1900-0000-f303-47e431140000 pid=5169->guuid=203f2b6b-1900-0000-f303-47e432140000 pid=5170 execve guuid=e0bd4282-1900-0000-f303-47e435140000 pid=5173 /usr/bin/dash guuid=3238db52-1900-0000-f303-47e42e140000 pid=5172->guuid=e0bd4282-1900-0000-f303-47e435140000 pid=5173 execve guuid=ba57e782-1900-0000-f303-47e436140000 pid=5174 /usr/bin/pgrep guuid=e0bd4282-1900-0000-f303-47e435140000 pid=5173->guuid=ba57e782-1900-0000-f303-47e436140000 pid=5174 execve guuid=759ff9bb-1900-0000-f303-47e439140000 pid=5177 /usr/bin/dash guuid=3238db52-1900-0000-f303-47e42e140000 pid=5176->guuid=759ff9bb-1900-0000-f303-47e439140000 pid=5177 execve guuid=557295bc-1900-0000-f303-47e43a140000 pid=5178 /usr/sbin/killall5 guuid=759ff9bb-1900-0000-f303-47e439140000 pid=5177->guuid=557295bc-1900-0000-f303-47e43a140000 pid=5178 execve guuid=ef6866fa-1900-0000-f303-47e444140000 pid=5188 /usr/bin/dash guuid=3238db52-1900-0000-f303-47e42e140000 pid=5187->guuid=ef6866fa-1900-0000-f303-47e444140000 pid=5188 execve guuid=bf4c44fb-1900-0000-f303-47e445140000 pid=5189 /usr/bin/pgrep guuid=ef6866fa-1900-0000-f303-47e444140000 pid=5188->guuid=bf4c44fb-1900-0000-f303-47e445140000 pid=5189 execve guuid=e3c32b3a-1a00-0000-f303-47e448140000 pid=5192 /usr/bin/dash guuid=3238db52-1900-0000-f303-47e42e140000 pid=5191->guuid=e3c32b3a-1a00-0000-f303-47e448140000 pid=5192 execve guuid=440dc03a-1a00-0000-f303-47e449140000 pid=5193 /usr/sbin/killall5 guuid=e3c32b3a-1a00-0000-f303-47e448140000 pid=5192->guuid=440dc03a-1a00-0000-f303-47e449140000 pid=5193 execve guuid=6b46d586-1a00-0000-f303-47e44b140000 pid=5195 /usr/bin/systemctl guuid=201a2d86-1a00-0000-f303-47e44a140000 pid=5194->guuid=6b46d586-1a00-0000-f303-47e44b140000 pid=5195 execve guuid=62d951c7-1a00-0000-f303-47e461140000 pid=5217 /usr/bin/systemctl guuid=2c141ec7-1a00-0000-f303-47e460140000 pid=5216->guuid=62d951c7-1a00-0000-f303-47e461140000 pid=5217 execve guuid=51178e0e-1b00-0000-f303-47e47f140000 pid=5247 /usr/bin/systemctl guuid=dc3f400e-1b00-0000-f303-47e47d140000 pid=5245->guuid=51178e0e-1b00-0000-f303-47e47f140000 pid=5247 execve guuid=2fdaba13-0000-0000-f303-47e401000000 pid=1 /usr/lib/systemd/systemd guuid=f7fc4110-1b00-0000-f303-47e481140000 pid=5249 /usr/sbin/uplugplay mprotect-exec guuid=2fdaba13-0000-0000-f303-47e401000000 pid=1->guuid=f7fc4110-1b00-0000-f303-47e481140000 pid=5249 execve guuid=810ceb1a-1b00-0000-f303-47e486140000 pid=5254 /usr/sbin/uplugplay guuid=f7fc4110-1b00-0000-f303-47e481140000 pid=5249->guuid=810ceb1a-1b00-0000-f303-47e486140000 pid=5254 clone guuid=730c0f1b-1b00-0000-f303-47e487140000 pid=5255 /usr/bin/dash guuid=810ceb1a-1b00-0000-f303-47e486140000 pid=5254->guuid=730c0f1b-1b00-0000-f303-47e487140000 pid=5255 execve guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256 /usr/sbin/uplugplay dns mprotect-exec net send-data write-config guuid=730c0f1b-1b00-0000-f303-47e487140000 pid=5255->guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256 execve 72feda4e-8ff4-5eee-be80-abecb8d0eda9 103.176.111.176:80 guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256->72feda4e-8ff4-5eee-be80-abecb8d0eda9 send: 78B 99a07b9c-a06a-5036-a75d-39daa574df85 255.255.255.255:53 guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256->99a07b9c-a06a-5036-a75d-39daa574df85 send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5258 /usr/sbin/uplugplay guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256->guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5258 clone guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5259 /usr/sbin/uplugplay guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256->guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5259 clone guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5260 /usr/sbin/uplugplay guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256->guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5260 clone guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5266 /usr/sbin/uplugplay guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256->guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5266 clone guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5267 /usr/sbin/uplugplay guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256->guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5267 clone guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5270 /usr/sbin/uplugplay guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256->guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5270 clone guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5271 /usr/sbin/uplugplay guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5256->guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5271 clone guuid=bdbf9626-1b00-0000-f303-47e48d140000 pid=5261 /usr/bin/dash guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5260->guuid=bdbf9626-1b00-0000-f303-47e48d140000 pid=5261 execve guuid=b0cbd126-1b00-0000-f303-47e48e140000 pid=5262 /usr/bin/hostnamectl guuid=bdbf9626-1b00-0000-f303-47e48d140000 pid=5261->guuid=b0cbd126-1b00-0000-f303-47e48e140000 pid=5262 execve guuid=3a444134-1b00-0000-f303-47e494140000 pid=5268 /usr/bin/dash guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5267->guuid=3a444134-1b00-0000-f303-47e494140000 pid=5268 execve guuid=85b07034-1b00-0000-f303-47e495140000 pid=5269 /usr/bin/uptime guuid=3a444134-1b00-0000-f303-47e494140000 pid=5268->guuid=85b07034-1b00-0000-f303-47e495140000 pid=5269 execve guuid=ceed8835-1b00-0000-f303-47e498140000 pid=5272 /usr/bin/dash guuid=ba85391b-1b00-0000-f303-47e488140000 pid=5271->guuid=ceed8835-1b00-0000-f303-47e498140000 pid=5272 execve guuid=c3deb435-1b00-0000-f303-47e499140000 pid=5273 /usr/bin/uname guuid=ceed8835-1b00-0000-f303-47e498140000 pid=5272->guuid=c3deb435-1b00-0000-f303-47e499140000 pid=5273 execve
Threat name:
Linux.Trojan.Prometei
Status:
Malicious
First seen:
2026-07-02 13:25:54 UTC
File Type:
ELF64 Little (Exe)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
prometei_elf
Score:
  10/10
Tags:
family:prometei_elf botnet discovery linux miner persistence privilege_escalation upx
Behaviour
Reads runtime system information
Reads CPU attributes
UPX packed file
Enumerates running processes
Modifies systemd
Write file to user bin folder
Deletes itself
Modifies hosts file
Family: Prometei
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments