MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f0aa83bbbd2c75e2f71ec16029ee5fcfad59f3a8efa30a500b815f0f6c18d987. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: f0aa83bbbd2c75e2f71ec16029ee5fcfad59f3a8efa30a500b815f0f6c18d987
SHA3-384 hash: 45e2b1cc8a7ffde348598f4c87a2294d7b512c8c9c90dc2f2a0f77b3e7ebfa225ccf8ea8fe87ce25fe60d426b644b0b2
SHA1 hash: 94e6098bab3b1d1d2930ab87e0f82f5fe3ac1d7b
MD5 hash: 1f47ecc10bc008ad26e504897b940f22
humanhash: indigo-carbon-river-virginia
File name:f0aa83bbbd2c75e2f71ec16029ee5fcfad59f3a8efa30a500b815f0f6c18d987
Download: download sample
Signature Prometei
File size:1'989'056 bytes
First seen:2026-07-30 21:18:08 UTC
Last seen:2026-07-31 18:16:23 UTC
File type: elf
MIME type:application/x-executable
ssdeep 49152:YrtUegEsxwWb+vck/XialwAyaIkY5JN1DByF1IzjrojaQeS7sf:YrnsTw9/vy0mN1Hnasf
TLSH T198953328DE2CEAED8237AB645A90C2CFCFC41E453A2FE551297C91BC53DD4E69C43848
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter c2hunter
Tags:elf Prometei UPX wraith
File size (compressed) :1'989'056 bytes
File size (de-compressed) :5'199'952 bytes
Format:linux/amd64
Unpacked file: a0f85de525c9f1126dd701b4b9a50237ef6dd1605836da64e983e49a2c50d268

Intelligence


File Origin
# of uploads :
9
# of downloads :
86
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creating a file
Sends data to a server
Collects information on the RAM
Connection attempt
Locks files
Receives data from a server
Changes access rights for a written file
Kills processes
Changes the time when the file was created, accessed, or modified
Runs as daemon
Collects information on the CPU
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Performs a bruteforce attack in the network
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
UPX
Botnet:
unknown
Number of open files:
68
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=62b6b1ce-1600-0000-bbe1-e2f50a0d0000 pid=3338 /usr/bin/sudo guuid=da3249d0-1600-0000-bbe1-e2f5100d0000 pid=3344 /tmp/sample.bin mprotect-exec write-file guuid=62b6b1ce-1600-0000-bbe1-e2f50a0d0000 pid=3338->guuid=da3249d0-1600-0000-bbe1-e2f5100d0000 pid=3344 execve guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3399 /tmp/sample.bin net zombie guuid=da3249d0-1600-0000-bbe1-e2f5100d0000 pid=3344->guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3399 clone 5ae18a07-f053-5a60-99ed-4d9d3e20c696 1.1.1.1:853 guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3399->5ae18a07-f053-5a60-99ed-4d9d3e20c696 con caec5668-d34a-5eb7-86d9-4f5a59806182 45.148.10.144:21370 guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3399->caec5668-d34a-5eb7-86d9-4f5a59806182 con 5f6004ab-135d-5863-8d6f-a6f76ba0720b 45.148.10.68:21370 guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3399->5f6004ab-135d-5863-8d6f-a6f76ba0720b con guuid=eb2a60ef-1600-0000-bbe1-e2f54c0d0000 pid=3404 /usr/bin/dash guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3399->guuid=eb2a60ef-1600-0000-bbe1-e2f54c0d0000 pid=3404 execve guuid=0bde9fef-1600-0000-bbe1-e2f54f0d0000 pid=3407 /tmp/sample.bin guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3399->guuid=0bde9fef-1600-0000-bbe1-e2f54f0d0000 pid=3407 clone guuid=67a2b4ef-1600-0000-bbe1-e2f5510d0000 pid=3409 /usr/bin/dash guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3399->guuid=67a2b4ef-1600-0000-bbe1-e2f5510d0000 pid=3409 execve guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3462 /tmp/sample.bin bpf-socket-filter net net-scan send-data write-config zombie guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3399->guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3462 clone guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3487 /tmp/sample.bin guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3399->guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3487 clone guuid=290986ef-1600-0000-bbe1-e2f54d0d0000 pid=3405 /usr/bin/dash guuid=eb2a60ef-1600-0000-bbe1-e2f54c0d0000 pid=3404->guuid=290986ef-1600-0000-bbe1-e2f54d0d0000 pid=3405 clone guuid=81258cef-1600-0000-bbe1-e2f54e0d0000 pid=3406 /usr/bin/dash guuid=eb2a60ef-1600-0000-bbe1-e2f54c0d0000 pid=3404->guuid=81258cef-1600-0000-bbe1-e2f54e0d0000 pid=3406 clone guuid=baa2a3ef-1600-0000-bbe1-e2f5500d0000 pid=3408 /tmp/sample.bin zombie guuid=0bde9fef-1600-0000-bbe1-e2f54f0d0000 pid=3407->guuid=baa2a3ef-1600-0000-bbe1-e2f5500d0000 pid=3408 clone guuid=939469f0-1600-0000-bbe1-e2f5540d0000 pid=3412 /usr/sbin/xtables-nft-multi guuid=67a2b4ef-1600-0000-bbe1-e2f5510d0000 pid=3409->guuid=939469f0-1600-0000-bbe1-e2f5540d0000 pid=3412 execve guuid=495f4dff-1600-0000-bbe1-e2f56c0d0000 pid=3436 /usr/sbin/xtables-nft-multi guuid=67a2b4ef-1600-0000-bbe1-e2f5510d0000 pid=3409->guuid=495f4dff-1600-0000-bbe1-e2f56c0d0000 pid=3436 execve guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3462|network network activity to 2052 IP addresses review logs to see them all guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3462->guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3462|network network guuid=941fa812-1700-0000-bbe1-e2f5920d0000 pid=3474 /usr/bin/dash guuid=cc753eed-1600-0000-bbe1-e2f5470d0000 pid=3462->guuid=941fa812-1700-0000-bbe1-e2f5920d0000 pid=3474 execve guuid=57081413-1700-0000-bbe1-e2f5940d0000 pid=3476 /usr/sbin/xtables-nft-multi guuid=941fa812-1700-0000-bbe1-e2f5920d0000 pid=3474->guuid=57081413-1700-0000-bbe1-e2f5940d0000 pid=3476 execve guuid=b2738413-1700-0000-bbe1-e2f5960d0000 pid=3478 /usr/sbin/xtables-nft-multi guuid=941fa812-1700-0000-bbe1-e2f5920d0000 pid=3474->guuid=b2738413-1700-0000-bbe1-e2f5960d0000 pid=3478 execve guuid=16fef313-1700-0000-bbe1-e2f5980d0000 pid=3480 /usr/sbin/xtables-nft-multi guuid=941fa812-1700-0000-bbe1-e2f5920d0000 pid=3474->guuid=16fef313-1700-0000-bbe1-e2f5980d0000 pid=3480 execve guuid=346e6214-1700-0000-bbe1-e2f59a0d0000 pid=3482 /usr/sbin/xtables-nft-multi guuid=941fa812-1700-0000-bbe1-e2f5920d0000 pid=3474->guuid=346e6214-1700-0000-bbe1-e2f59a0d0000 pid=3482 execve
Result
Malware family:
n/a
Score:
  9/10
Tags:
antivm command_and_control defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads hardware information
Reads network interface configuration
Creates Raw socket
Flushes firewall rules
Outbound SSH connection to public host
Unexpected DNS network traffic destination
Contacts a large (366815) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Prometei

elf f0aa83bbbd2c75e2f71ec16029ee5fcfad59f3a8efa30a500b815f0f6c18d987

(this sample)

  
Delivery method
Distributed via web download

Comments