MB-a5073027d44c6ce3d7b0b8b29e4cfefb509665c4c25848e75522ebd7eb17c836
high
📛 Threat Title
Prometei: a5073027d44c6ce3d7b0b8b29e4cfefb509665c4c25848e75522ebd7eb17c836
Description
File type: elf. Size: 449088 bytes. Tags: elf, Prometei, wraith. Reporter: c2hunter. First seen: 2026-08-04 22:07:07.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
a5073027d44c6ce3d7b0b8b29e4cfefb509665c4c25848e75522ebd7eb17c836
IOC database
- Type
- hash_sha256
- Value
a5073027d44c6ce3d7b0b8b29e4cfefb509665c4c25848e75522ebd7eb17c836- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Prometei
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
2cfc74c230d1c370d157e651ea3066f341b0206f
IOC database
- Type
- hash_sha1
- Value
2cfc74c230d1c370d157e651ea3066f341b0206f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
3c480e63ebeb2bd7dc3846b216d34886
IOC database
- Type
- hash_md5
- Value
3c480e63ebeb2bd7dc3846b216d34886- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 449088 bytes. Tags: elf, Prometei, wraith. Reporter: c2hunter. First seen: 2026-08-04 22:07:07.
Remediations (10)
-
web:any.run
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
-
web:cyberpress.org
eSentire's Threat Response Unit (TRU) spotted Prometei , a Russian-linked botnet active since 2016, hitting a construction firm's Windows Server. This modular malware grabs remote control, steals credentials, mines Monero crypto, spreads laterally, and locks out rivals with self-defense tricks.
-
web:github.com
This repository contains a technical analysis of the Prometei Botnet, documented in PDF format. The report examines its infection lifecycle, persistence mechanisms, lateral movement techniques, command-and-control infrastructure, incident response procedures, and defensive recommendations.
-
web:prometheus.io
An open-source monitoring system with a dimensional data model, flexible query language, efficient time series database and modern alerting approach.
-
web:rewterz.com
Prometei Malware - Active IOCs Severity High Analysis Summary Prometei is a sophisticated modular botnet malware that was first identified in 2016, with increased activity observed since 2020.
-
web:socprime.com
Prometei is a Russia-linked botnet that compromises Windows servers, installs a persistent service, steals credentials, mines Monero, and hardens the host to block competing intruders.
-
web:unit42.paloaltonetworks.com
We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features. We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features.
-
web:www.darkreading.com
An 8-year-old modular botnet is still kicking, spreading a cryptojacker and Web shell on machines spread across multiple continents. " Prometei " was first discovered in 2020, but later evidence ...
-
web:www.securitricks.com
Prometei on Securitricks: related threat intelligence, IOCs, and MITRE context.
-
web:www.securityweek.com
An updated variant of the Prometei malware is making the rounds, and activity associated with the botnet has surged over the past months, Palo Alto Networks reports. A modular botnet initially discovered in July 2020, Prometei targets both Windows and Linux systems for infection, primarily for cryptocurrency mining and credential exfiltration.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.