MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f77d14298ce747794bfca03d33625dfbcd9cef965c2eff0edefd9ebdd5665a76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 7


Intelligence 7 IOCs YARA 4 File information Comments

SHA256 hash: f77d14298ce747794bfca03d33625dfbcd9cef965c2eff0edefd9ebdd5665a76
SHA3-384 hash: cb27adb13692119fe0a88ce65a6146fc5e3837ca0c621dafae94e0ff638c2d9b9249cc2ee26e738bce08025e39fe7b41
SHA1 hash: 139f872d128ae59ea3423b360612a020560d692a
MD5 hash: 4ee3fd65856a7346485c0dacd755fef4
humanhash: twelve-texas-papa-november
File name:f77d14298ce747794bfca03d33625dfbcd9cef965c2eff0edefd9ebdd5665a76
Download: download sample
Signature Prometei
File size:449'084 bytes
First seen:2026-05-16 01:43:21 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:Fs+/py5fM2l+M5F7TsJwtY1yvr+bT1psS+6T6NCj76tsdN:Fs6pyCC/Ya2hpi6T6N4H
TLSH T14FA423B4F9219E9F6DD769B91B24831DE182C172589D4C2313AE94E34F3D632BF2C816
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter c2hunter
Tags:elf Prometei wraith

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
140
Number of processes launched:
85
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Persistence
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=3e3fa27f-1a00-0000-ff92-e779c20c0000 pid=3266 /usr/bin/sudo guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276 /tmp/sample.bin delete-file mprotect-exec write-file guuid=3e3fa27f-1a00-0000-ff92-e779c20c0000 pid=3266->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276 execve guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3306 /tmp/sample.bin guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3306 clone guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3307 /tmp/sample.bin guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3307 clone guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3321 /tmp/sample.bin guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3321 clone guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3322 /tmp/sample.bin guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3322 clone guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3452 /tmp/sample.bin guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3452 clone guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3453 /tmp/sample.bin guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3453 clone guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3578 /tmp/sample.bin guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3578 clone guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3579 /tmp/sample.bin guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3579 clone guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3723 /tmp/sample.bin guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3723 clone guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3724 /tmp/sample.bin guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3724 clone guuid=5e238aaf-1b00-0000-ff92-e779610f0000 pid=3937 /usr/bin/dash guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=5e238aaf-1b00-0000-ff92-e779610f0000 pid=3937 execve guuid=eb7742ef-1b00-0000-ff92-e77916100000 pid=4118 /usr/bin/dash guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=eb7742ef-1b00-0000-ff92-e77916100000 pid=4118 execve guuid=42146a17-1c00-0000-ff92-e779c1100000 pid=4289 /usr/bin/dash guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3276->guuid=42146a17-1c00-0000-ff92-e779c1100000 pid=4289 execve guuid=22ec9f9a-1a00-0000-ff92-e779ec0c0000 pid=3308 /usr/bin/dash guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3307->guuid=22ec9f9a-1a00-0000-ff92-e779ec0c0000 pid=3308 execve guuid=5c72169b-1a00-0000-ff92-e779ed0c0000 pid=3309 /usr/bin/pgrep guuid=22ec9f9a-1a00-0000-ff92-e779ec0c0000 pid=3308->guuid=5c72169b-1a00-0000-ff92-e779ed0c0000 pid=3309 execve guuid=d39218b1-1a00-0000-ff92-e779fc0c0000 pid=3324 /usr/bin/dash guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3322->guuid=d39218b1-1a00-0000-ff92-e779fc0c0000 pid=3324 execve guuid=5ade46b1-1a00-0000-ff92-e779fd0c0000 pid=3325 /usr/bin/pgrep guuid=d39218b1-1a00-0000-ff92-e779fc0c0000 pid=3324->guuid=5ade46b1-1a00-0000-ff92-e779fd0c0000 pid=3325 execve guuid=fafa19ef-1a00-0000-ff92-e7797e0d0000 pid=3454 /usr/bin/dash guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3453->guuid=fafa19ef-1a00-0000-ff92-e7797e0d0000 pid=3454 execve guuid=2c274cef-1a00-0000-ff92-e779800d0000 pid=3456 /usr/sbin/killall5 guuid=fafa19ef-1a00-0000-ff92-e7797e0d0000 pid=3454->guuid=2c274cef-1a00-0000-ff92-e779800d0000 pid=3456 execve guuid=4921bc32-1b00-0000-ff92-e779fc0d0000 pid=3580 /usr/bin/dash guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3579->guuid=4921bc32-1b00-0000-ff92-e779fc0d0000 pid=3580 execve guuid=f250f132-1b00-0000-ff92-e779fd0d0000 pid=3581 /usr/bin/pgrep guuid=4921bc32-1b00-0000-ff92-e779fc0d0000 pid=3580->guuid=f250f132-1b00-0000-ff92-e779fd0d0000 pid=3581 execve guuid=677c6f70-1b00-0000-ff92-e7798d0e0000 pid=3725 /usr/bin/dash guuid=7d2a0982-1a00-0000-ff92-e779cc0c0000 pid=3724->guuid=677c6f70-1b00-0000-ff92-e7798d0e0000 pid=3725 execve guuid=0346d270-1b00-0000-ff92-e7798e0e0000 pid=3726 /usr/sbin/killall5 guuid=677c6f70-1b00-0000-ff92-e7798d0e0000 pid=3725->guuid=0346d270-1b00-0000-ff92-e7798e0e0000 pid=3726 execve guuid=bfa600b0-1b00-0000-ff92-e779640f0000 pid=3940 /usr/bin/systemctl guuid=5e238aaf-1b00-0000-ff92-e779610f0000 pid=3937->guuid=bfa600b0-1b00-0000-ff92-e779640f0000 pid=3940 execve guuid=6c616bef-1b00-0000-ff92-e77918100000 pid=4120 /usr/bin/systemctl guuid=eb7742ef-1b00-0000-ff92-e77916100000 pid=4118->guuid=6c616bef-1b00-0000-ff92-e77918100000 pid=4120 execve guuid=bb379517-1c00-0000-ff92-e779c2100000 pid=4290 /usr/bin/systemctl guuid=42146a17-1c00-0000-ff92-e779c1100000 pid=4289->guuid=bb379517-1c00-0000-ff92-e779c2100000 pid=4290 execve guuid=2fdaba13-0000-0000-ff92-e77901000000 pid=1 /usr/lib/systemd/systemd guuid=9bba1419-1c00-0000-ff92-e779cb100000 pid=4299 /usr/sbin/uplugplay mprotect-exec guuid=2fdaba13-0000-0000-ff92-e77901000000 pid=1->guuid=9bba1419-1c00-0000-ff92-e779cb100000 pid=4299 execve guuid=9c5ace27-1c00-0000-ff92-e77906110000 pid=4358 /usr/sbin/uplugplay guuid=9bba1419-1c00-0000-ff92-e779cb100000 pid=4299->guuid=9c5ace27-1c00-0000-ff92-e77906110000 pid=4358 clone guuid=f468fd27-1c00-0000-ff92-e7790a110000 pid=4362 /usr/bin/dash guuid=9c5ace27-1c00-0000-ff92-e77906110000 pid=4358->guuid=f468fd27-1c00-0000-ff92-e7790a110000 pid=4362 execve guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363 /usr/sbin/uplugplay dns mprotect-exec net send-data write-config guuid=f468fd27-1c00-0000-ff92-e7790a110000 pid=4362->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363 execve 72feda4e-8ff4-5eee-be80-abecb8d0eda9 103.176.111.176:80 guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->72feda4e-8ff4-5eee-be80-abecb8d0eda9 send: 1077B 99a07b9c-a06a-5036-a75d-39daa574df85 255.255.255.255:53 guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->99a07b9c-a06a-5036-a75d-39daa574df85 send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4413 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4413 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4472 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4472 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4473 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4473 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4539 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4539 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4540 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4540 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4550 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4550 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4551 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4551 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4579 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4579 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4580 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4580 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4591 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4591 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4592 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4592 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4599 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4599 clone guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4600 /usr/sbin/uplugplay guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4363->guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4600 clone guuid=1430634e-1c00-0000-ff92-e7797a110000 pid=4474 /usr/bin/dash guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4473->guuid=1430634e-1c00-0000-ff92-e7797a110000 pid=4474 execve guuid=345ba14e-1c00-0000-ff92-e7797e110000 pid=4478 /usr/bin/hostnamectl guuid=1430634e-1c00-0000-ff92-e7797a110000 pid=4474->guuid=345ba14e-1c00-0000-ff92-e7797e110000 pid=4478 execve guuid=c38d395c-1c00-0000-ff92-e779bd110000 pid=4541 /usr/bin/dash guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4540->guuid=c38d395c-1c00-0000-ff92-e779bd110000 pid=4541 execve guuid=c48b6c5c-1c00-0000-ff92-e779c1110000 pid=4545 /usr/bin/uptime guuid=c38d395c-1c00-0000-ff92-e779bd110000 pid=4541->guuid=c48b6c5c-1c00-0000-ff92-e779c1110000 pid=4545 execve guuid=15718d5d-1c00-0000-ff92-e779c9110000 pid=4553 /usr/bin/dash guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4551->guuid=15718d5d-1c00-0000-ff92-e779c9110000 pid=4553 execve guuid=20b6b95d-1c00-0000-ff92-e779ca110000 pid=4554 /usr/bin/uname guuid=15718d5d-1c00-0000-ff92-e779c9110000 pid=4553->guuid=20b6b95d-1c00-0000-ff92-e779ca110000 pid=4554 execve guuid=30ae8664-1c00-0000-ff92-e779e5110000 pid=4581 /usr/bin/dash guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4580->guuid=30ae8664-1c00-0000-ff92-e779e5110000 pid=4581 execve guuid=48eeb364-1c00-0000-ff92-e779e6110000 pid=4582 /usr/bin/hostnamectl guuid=30ae8664-1c00-0000-ff92-e779e5110000 pid=4581->guuid=48eeb364-1c00-0000-ff92-e779e6110000 pid=4582 execve guuid=da8e2b68-1c00-0000-ff92-e779f2110000 pid=4594 /usr/bin/dash guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4592->guuid=da8e2b68-1c00-0000-ff92-e779f2110000 pid=4594 execve guuid=f7545c68-1c00-0000-ff92-e779f3110000 pid=4595 /usr/bin/uptime guuid=da8e2b68-1c00-0000-ff92-e779f2110000 pid=4594->guuid=f7545c68-1c00-0000-ff92-e779f3110000 pid=4595 execve guuid=bb677c69-1c00-0000-ff92-e779f9110000 pid=4601 /usr/bin/dash guuid=059c3328-1c00-0000-ff92-e7790b110000 pid=4600->guuid=bb677c69-1c00-0000-ff92-e779f9110000 pid=4601 execve guuid=c261ab69-1c00-0000-ff92-e779fb110000 pid=4603 /usr/bin/uname guuid=bb677c69-1c00-0000-ff92-e779f9110000 pid=4601->guuid=c261ab69-1c00-0000-ff92-e779fb110000 pid=4603 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-16 01:44:41 UTC
File Type:
ELF64 Little (Exe)
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
prometei_elf
Score:
  10/10
Tags:
family:prometei_elf botnet discovery linux miner persistence privilege_escalation upx
Behaviour
Reads runtime system information
Reads CPU attributes
UPX packed file
Enumerates running processes
Modifies systemd
Write file to user bin folder
Deletes itself
Modifies hosts file
Family: Prometei
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments