MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fda60092e105b9fa1f7b94062f3defaefff215ca1cc8e2e58bca67c55e2f2958. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Prometei


Vendor detections: 9


Intelligence 9 IOCs YARA 4 File information Comments

SHA256 hash: fda60092e105b9fa1f7b94062f3defaefff215ca1cc8e2e58bca67c55e2f2958
SHA3-384 hash: c12503931c0b2317f236ca904bb9cdda217ce387a3fbc31e82e354759b353e6f0e92cf308dd2d3ec12c71d2c16c9754c
SHA1 hash: 5258d9919df434973fa9767e7bc1e8ad16f42046
MD5 hash: c92c715700e8fcc2b019d0c60442ca4e
humanhash: jupiter-orange-alabama-twenty
File name:fda60092e105b9fa1f7b94062f3defaefff215ca1cc8e2e58bca67c55e2f2958
Download: download sample
Signature Prometei
File size:449'087 bytes
First seen:2026-06-27 12:47:47 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:Fs+/py5fM2l+M5F7TsJwtY1yvr+bT1psS+6T6NCj76tsds:Fs6pyCC/Ya2hpi6T6N4O
TLSH T1E3A423B4F9219E8F6DD769B91B24C31DE182C172589D4C2313AE94A34F3D632BF2C816
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter c2hunter
Tags:elf Prometei wraith

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Collects information on the OS
Changes access rights for a written file
Collects information on the CPU
Kills processes
Launching a process
Manages services
Writes files to system subdirectory
Writes files to system directory
Deleting of the original file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-06-27T10:13:00Z UTC
Last seen:
2026-06-28T00:32:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=b99abe50-2000-0000-7937-d0e9b9130000 pid=5049 /usr/bin/sudo guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055 /tmp/sample.bin delete-file mprotect-exec write-file guuid=b99abe50-2000-0000-7937-d0e9b9130000 pid=5049->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055 execve guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5104 /tmp/sample.bin guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5104 clone guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5105 /tmp/sample.bin guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5105 clone guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5120 /tmp/sample.bin guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5120 clone guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5121 /tmp/sample.bin guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5121 clone guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5194 /tmp/sample.bin guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5194 clone guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5203 /tmp/sample.bin guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5203 clone guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5206 /tmp/sample.bin guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5206 clone guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5207 /tmp/sample.bin guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5207 clone guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5210 /tmp/sample.bin guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5210 clone guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5211 /tmp/sample.bin guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5211 clone guuid=19c0b376-2100-0000-7937-d0e95e140000 pid=5214 /usr/bin/dash guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=19c0b376-2100-0000-7937-d0e95e140000 pid=5214 execve guuid=f4b3a7c0-2100-0000-7937-d0e975140000 pid=5237 /usr/bin/dash guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=f4b3a7c0-2100-0000-7937-d0e975140000 pid=5237 execve guuid=d8a8ff18-2200-0000-7937-d0e991140000 pid=5265 /usr/bin/dash guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5055->guuid=d8a8ff18-2200-0000-7937-d0e991140000 pid=5265 execve guuid=7ddea977-2000-0000-7937-d0e9f2130000 pid=5106 /usr/bin/dash guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5105->guuid=7ddea977-2000-0000-7937-d0e9f2130000 pid=5106 execve guuid=260cf777-2000-0000-7937-d0e9f4130000 pid=5108 /usr/bin/pgrep guuid=7ddea977-2000-0000-7937-d0e9f2130000 pid=5106->guuid=260cf777-2000-0000-7937-d0e9f4130000 pid=5108 execve guuid=da34ba7c-2000-0000-7937-d0e903140000 pid=5123 /usr/bin/dash guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5121->guuid=da34ba7c-2000-0000-7937-d0e903140000 pid=5123 execve guuid=37ad097d-2000-0000-7937-d0e905140000 pid=5125 /usr/bin/pgrep guuid=da34ba7c-2000-0000-7937-d0e903140000 pid=5123->guuid=37ad097d-2000-0000-7937-d0e905140000 pid=5125 execve guuid=a21859c0-2000-0000-7937-d0e954140000 pid=5204 /usr/bin/dash guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5203->guuid=a21859c0-2000-0000-7937-d0e954140000 pid=5204 execve guuid=ef1398c0-2000-0000-7937-d0e955140000 pid=5205 /usr/sbin/killall5 guuid=a21859c0-2000-0000-7937-d0e954140000 pid=5204->guuid=ef1398c0-2000-0000-7937-d0e955140000 pid=5205 execve guuid=905013fa-2000-0000-7937-d0e958140000 pid=5208 /usr/bin/dash guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5207->guuid=905013fa-2000-0000-7937-d0e958140000 pid=5208 execve guuid=9e1255fa-2000-0000-7937-d0e959140000 pid=5209 /usr/bin/pgrep guuid=905013fa-2000-0000-7937-d0e958140000 pid=5208->guuid=9e1255fa-2000-0000-7937-d0e959140000 pid=5209 execve guuid=71d77038-2100-0000-7937-d0e95c140000 pid=5212 /usr/bin/dash guuid=8397ad53-2000-0000-7937-d0e9bf130000 pid=5211->guuid=71d77038-2100-0000-7937-d0e95c140000 pid=5212 execve guuid=7170b538-2100-0000-7937-d0e95d140000 pid=5213 /usr/sbin/killall5 guuid=71d77038-2100-0000-7937-d0e95c140000 pid=5212->guuid=7170b538-2100-0000-7937-d0e95d140000 pid=5213 execve guuid=29c76f77-2100-0000-7937-d0e95f140000 pid=5215 /usr/bin/systemctl guuid=19c0b376-2100-0000-7937-d0e95e140000 pid=5214->guuid=29c76f77-2100-0000-7937-d0e95f140000 pid=5215 execve guuid=ef64dac0-2100-0000-7937-d0e976140000 pid=5238 /usr/bin/systemctl guuid=f4b3a7c0-2100-0000-7937-d0e975140000 pid=5237->guuid=ef64dac0-2100-0000-7937-d0e976140000 pid=5238 execve guuid=43633d19-2200-0000-7937-d0e992140000 pid=5266 /usr/bin/systemctl guuid=d8a8ff18-2200-0000-7937-d0e991140000 pid=5265->guuid=43633d19-2200-0000-7937-d0e992140000 pid=5266 execve guuid=2fdaba13-0000-0000-7937-d0e901000000 pid=1 /usr/lib/systemd/systemd guuid=fddbed1b-2200-0000-7937-d0e993140000 pid=5267 /usr/sbin/uplugplay mprotect-exec guuid=2fdaba13-0000-0000-7937-d0e901000000 pid=1->guuid=fddbed1b-2200-0000-7937-d0e993140000 pid=5267 execve guuid=c3e2e92a-2200-0000-7937-d0e994140000 pid=5268 /usr/sbin/uplugplay guuid=fddbed1b-2200-0000-7937-d0e993140000 pid=5267->guuid=c3e2e92a-2200-0000-7937-d0e994140000 pid=5268 clone guuid=25e9442b-2200-0000-7937-d0e995140000 pid=5269 /usr/bin/dash guuid=c3e2e92a-2200-0000-7937-d0e994140000 pid=5268->guuid=25e9442b-2200-0000-7937-d0e995140000 pid=5269 execve guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270 /usr/sbin/uplugplay dns mprotect-exec net send-data write-config guuid=25e9442b-2200-0000-7937-d0e995140000 pid=5269->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270 execve 72feda4e-8ff4-5eee-be80-abecb8d0eda9 103.176.111.176:80 guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->72feda4e-8ff4-5eee-be80-abecb8d0eda9 send: 862B 99a07b9c-a06a-5036-a75d-39daa574df85 255.255.255.255:53 guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->99a07b9c-a06a-5036-a75d-39daa574df85 send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5271 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5271 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5272 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5272 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5273 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5273 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5277 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5277 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5278 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5278 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5281 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5281 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5282 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5282 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5283 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5283 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5285 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5285 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5289 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5289 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5290 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5290 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5293 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5293 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5294 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5294 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5330 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5330 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5331 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5331 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5334 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5334 clone guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5335 /usr/sbin/uplugplay guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5270->guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5335 clone guuid=bce26e6b-2200-0000-7937-d0e99a140000 pid=5274 /usr/bin/dash guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5273->guuid=bce26e6b-2200-0000-7937-d0e99a140000 pid=5274 execve guuid=4552e96b-2200-0000-7937-d0e99b140000 pid=5275 /usr/bin/hostnamectl guuid=bce26e6b-2200-0000-7937-d0e99a140000 pid=5274->guuid=4552e96b-2200-0000-7937-d0e99b140000 pid=5275 execve guuid=52b57388-2200-0000-7937-d0e99f140000 pid=5279 /usr/bin/dash guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5278->guuid=52b57388-2200-0000-7937-d0e99f140000 pid=5279 execve guuid=07055a8a-2200-0000-7937-d0e9a0140000 pid=5280 /usr/bin/hostnamectl guuid=52b57388-2200-0000-7937-d0e99f140000 pid=5279->guuid=07055a8a-2200-0000-7937-d0e9a0140000 pid=5280 execve guuid=cdc98fa5-2200-0000-7937-d0e9a4140000 pid=5284 /usr/bin/dash guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5282->guuid=cdc98fa5-2200-0000-7937-d0e9a4140000 pid=5284 execve guuid=216041a6-2200-0000-7937-d0e9a6140000 pid=5286 /usr/bin/uptime guuid=cdc98fa5-2200-0000-7937-d0e9a4140000 pid=5284->guuid=216041a6-2200-0000-7937-d0e9a6140000 pid=5286 execve guuid=77afb8a6-2200-0000-7937-d0e9a7140000 pid=5287 /usr/bin/dash guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5285->guuid=77afb8a6-2200-0000-7937-d0e9a7140000 pid=5287 execve guuid=4dfa60a7-2200-0000-7937-d0e9a8140000 pid=5288 /usr/bin/uptime guuid=77afb8a6-2200-0000-7937-d0e9a7140000 pid=5287->guuid=4dfa60a7-2200-0000-7937-d0e9a8140000 pid=5288 execve guuid=44be2aac-2200-0000-7937-d0e9ab140000 pid=5291 /usr/bin/dash guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5290->guuid=44be2aac-2200-0000-7937-d0e9ab140000 pid=5291 execve guuid=e8ff1fad-2200-0000-7937-d0e9ac140000 pid=5292 /usr/bin/uname guuid=44be2aac-2200-0000-7937-d0e9ab140000 pid=5291->guuid=e8ff1fad-2200-0000-7937-d0e9ac140000 pid=5292 execve guuid=5ff008b0-2200-0000-7937-d0e9af140000 pid=5295 /usr/bin/dash send-data guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5294->guuid=5ff008b0-2200-0000-7937-d0e9af140000 pid=5295 execve 5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 0.0.0.0:0 guuid=5ff008b0-2200-0000-7937-d0e9af140000 pid=5295->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 28B guuid=b51c7a0d-2a00-0000-7937-d0e9d4140000 pid=5332 /usr/bin/dash guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5331->guuid=b51c7a0d-2a00-0000-7937-d0e9d4140000 pid=5332 execve guuid=ae00ea0d-2a00-0000-7937-d0e9d5140000 pid=5333 /usr/bin/uptime guuid=b51c7a0d-2a00-0000-7937-d0e9d4140000 pid=5332->guuid=ae00ea0d-2a00-0000-7937-d0e9d5140000 pid=5333 execve guuid=7f291b10-2a00-0000-7937-d0e9d8140000 pid=5336 /usr/bin/dash guuid=ddcb2e2c-2200-0000-7937-d0e996140000 pid=5335->guuid=7f291b10-2a00-0000-7937-d0e9d8140000 pid=5336 execve guuid=fc9e9c10-2a00-0000-7937-d0e9d9140000 pid=5337 /usr/bin/uname guuid=7f291b10-2a00-0000-7937-d0e9d8140000 pid=5336->guuid=fc9e9c10-2a00-0000-7937-d0e9d9140000 pid=5337 execve
Threat name:
Linux.Trojan.Prometei
Status:
Malicious
First seen:
2026-06-27 12:48:32 UTC
File Type:
ELF64 Little (Exe)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
prometei_elf
Score:
  10/10
Tags:
family:prometei_elf botnet discovery linux miner persistence privilege_escalation upx
Behaviour
Reads runtime system information
Reads CPU attributes
UPX packed file
Enumerates running processes
Modifies systemd
Write file to user bin folder
Deletes itself
Modifies hosts file
Family: Prometei
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments