s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-0e6518062d007026012e15e87f993f51b5338a6317c69330db4671887817a26e high

📛 Threat Title

Prometei: 0e6518062d007026012e15e87f993f51b5338a6317c69330db4671887817a26e

Category: Prometei Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 449085 bytes. Tags: elf, Prometei, wraith. Reporter: c2hunter. First seen: 2026-08-04 22:08:04.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 0e6518062d007026012e15e87f993f51b5338a6317c69330db4671887817a26e

IOC database

Type
hash_sha256
Value
0e6518062d007026012e15e87f993f51b5338a6317c69330db4671887817a26e
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Prometei

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 0c7df2950889474de81430d89c0c1776686a267d

IOC database

Type
hash_sha1
Value
0c7df2950889474de81430d89c0c1776686a267d
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 dd8d47b19e413e031d9c8b40d49f136d

IOC database

Type
hash_md5
Value
dd8d47b19e413e031d9c8b40d49f136d
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 449085 bytes. Tags: elf, Prometei, wraith. Reporter: c2hunter. First seen: 2026-08-04 22:08:04.

Remediations (10)

  • web:any.run

    Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.

  • web:bazaar.abuse.ch

    Information on Prometei malware sample (SHA256 0e6518062d007026012e15e87f993f51b5338a6317c69330db4671887817a26e ) YARA Signatures MalwareBazaar uses YARA rules from ...

  • web:cyberpress.org

    eSentire's Threat Response Unit (TRU) spotted Prometei , a Russian-linked botnet active since 2016, hitting a construction firm's Windows Server. This modular malware grabs remote control, steals credentials, mines Monero crypto, spreads laterally, and locks out rivals with self-defense tricks.

  • web:github.com

    This repository contains a technical analysis of the Prometei Botnet, documented in PDF format. The report examines its infection lifecycle, persistence mechanisms, lateral movement techniques, command-and-control infrastructure, incident response procedures, and defensive recommendations.

  • web:rewterz.com

    Prometei Malware - Active IOCs Severity High Analysis Summary Prometei is a sophisticated modular botnet malware that was first identified in 2016, with increased activity observed since 2020.

  • web:socprime.com

    Prometei is a Russia-linked botnet that compromises Windows servers, installs a persistent service, steals credentials, mines Monero, and hardens the host to block competing intruders.

  • web:unit42.paloaltonetworks.com

    We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features. We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features.

  • web:www.cybereason.com

    Recently, the Cybereason Nocturnus Team responded to several incident response (IR) cases involving infections of the Prometei Botnet against companies in North America, observing that the attackers exploited recently published Microsoft Exchange vulnerabilities (CVE-2021-27065 and CVE-2021-26858) in order to penetrate the network and install malware. Prometei is a modular and multi-stage ...

  • web:www.darkreading.com

    An 8-year-old modular botnet is still kicking, spreading a cryptojacker and Web shell on machines spread across multiple continents. " Prometei " was first discovered in 2020, but later evidence ...

  • web:www.esentire.com

    Learn about the Prometei botnet that gets deployed on a Windows server, including a comprehensive breakdown of Prometei's technical operations, and how organizations can stay ahead of this threat.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.