MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 efcf7d27639d35b75eca73dde46b87ef103031d4c60de2f8d511bc11c49397de. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: efcf7d27639d35b75eca73dde46b87ef103031d4c60de2f8d511bc11c49397de
SHA3-384 hash: f511e87e9ad2566ff4fe86ce351e989208cea1af5baffe2d32acbf09e67832c57c1abd6f552c86941fd9533b951d1988
SHA1 hash: 17445b7ed339944538124114645930efb8709ac8
MD5 hash: 89681015d18fdd736bf3703a44aa73b1
humanhash: apart-texas-berlin-lemon
File name:efcf7d27639d35b75eca73dde46b87ef103031d4c60de2f8d511bc11c49397de
Download: download sample
Signature Prometei
File size:121 bytes
First seen:2026-08-01 01:56:19 UTC
Last seen:2026-08-01 18:29:41 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 3:TKH4vGBwkSDETLtWiL71u9GN3+GuVjLWgKoKWnQDFpKSbn:hBD6xXL7mGEjuXVDFbb
TLSH T1F7B092E962761E80F0285A05709A1C51BA868AA595586A69F88848BACD49601F106B15
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter c2hunter
Tags:Prometei sh wraith
URLMalware sample (SHA256 hash)SignatureTags
http://45.196.97.80/milan.armv7ln/an/awraith

Intelligence


File Origin
# of uploads :
3
# of downloads :
85
Origin country :
US US
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=1dfceba3-1900-0000-753d-df1aab0c0000 pid=3243 /usr/bin/sudo guuid=fcb999a7-1900-0000-753d-df1ab00c0000 pid=3248 /tmp/sample.bin guuid=1dfceba3-1900-0000-753d-df1aab0c0000 pid=3243->guuid=fcb999a7-1900-0000-753d-df1ab00c0000 pid=3248 execve guuid=d41712a8-1900-0000-753d-df1ab20c0000 pid=3250 /usr/bin/wget net send-data write-file guuid=fcb999a7-1900-0000-753d-df1ab00c0000 pid=3248->guuid=d41712a8-1900-0000-753d-df1ab20c0000 pid=3250 execve guuid=3a2a7eb1-1900-0000-753d-df1ac50c0000 pid=3269 /usr/bin/chmod guuid=fcb999a7-1900-0000-753d-df1ab00c0000 pid=3248->guuid=3a2a7eb1-1900-0000-753d-df1ac50c0000 pid=3269 execve guuid=ea45d4b1-1900-0000-753d-df1ac70c0000 pid=3271 /tmp/m zombie guuid=fcb999a7-1900-0000-753d-df1ab00c0000 pid=3248->guuid=ea45d4b1-1900-0000-753d-df1ac70c0000 pid=3271 execve e9ad79d0-aabf-59e0-a259-6705ab733842 45.196.97.80:80 guuid=d41712a8-1900-0000-753d-df1ab20c0000 pid=3250->e9ad79d0-aabf-59e0-a259-6705ab733842 send: 139B
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion linux
Behaviour
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Prometei

sh efcf7d27639d35b75eca73dde46b87ef103031d4c60de2f8d511bc11c49397de

(this sample)

  
Delivery method
Distributed via web download

Comments