MB-9fa5154073d4ce91fd659d8477b26a5f85c1259f18d950e4f3a4efa6e3452d5d
high
📛 Threat Title
Prometei: 9fa5154073d4ce91fd659d8477b26a5f85c1259f18d950e4f3a4efa6e3452d5d
Description
File type: elf. Size: 449088 bytes. Tags: cowrie, elf, honeypot, Prometei, x64. Reporter: aLittleBitGrey. First seen: 2026-09-25 09:17:21.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
9fa5154073d4ce91fd659d8477b26a5f85c1259f18d950e4f3a4efa6e3452d5d
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/9fa5154073d4ce91fd659d8477b26a5f85c1259f18d950e4f3a4efa6e3452d5d
IOC database
- Type
- hash_sha256
- Value
9fa5154073d4ce91fd659d8477b26a5f85c1259f18d950e4f3a4efa6e3452d5d- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Prometei
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/9fa5154073d4ce91fd659d8477b26a5f85c1259f18d950e4f3a4efa6e3452d5d
hash_sha1
6a1b43de356b503f80f25bb8007185599355f750
VT 26 / 75
IOC database
- Type
- hash_sha1
- Value
6a1b43de356b503f80f25bb8007185599355f750- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 26 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Linux.Prometei.5 |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Prometei |
| Arcabit | malicious | Trojan.Linux.Prometei.5 |
| Avast | malicious | ELF:Prometei-E [Trj] |
| AVG | malicious | ELF:Prometei-E [Trj] |
| Avira | malicious | TR/LINUX.Prometei.E |
| BitDefender | malicious | Trojan.Linux.Prometei.5 |
| ClamAV | malicious | Unix.Trojan.Prometei-10045451-0 |
| CTX | malicious | elf.trojan.prometei |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.BackDoor.Prometei.12 |
| Emsisoft | malicious | Trojan.Linux.Prometei.5 (B) |
| ESET-NOD32 | malicious | Linux/Prometei.B trojan |
| F-Secure | malicious | Trojan.TR/LINUX.Prometei.E |
| Fortinet | malicious | ELF/Prometei.12!tr |
| GData | malicious | Trojan.Linux.Prometei.5 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Prometei.c |
| Ikarus | malicious | Trojan.Linux.Prometei |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Prometei.a |
| Microsoft | malicious | Trojan:Linux/Coinminer.B |
| MicroWorld-eScan | malicious | Trojan.Linux.Prometei.5 |
| Rising | malicious | Backdoor.Prometei/Linux!1.DBE7 (CLASSIC) |
| SentinelOne | malicious | Static AI - Suspicious ELF |
| Tencent | malicious | Backdoor.Linux.Prometei.c |
| VIPRE | malicious | Trojan.Linux.Prometei.5 |
Details From VirusTotal
Basic Properties
| MD5 | 7170e4943d7715770b43ff55b64caeb0 |
| SHA-1 | 6a1b43de356b503f80f25bb8007185599355f750 |
| SHA-256 | 9fa5154073d4ce91fd659d8477b26a5f85c1259f18d950e4f3a4efa6e3452d5d |
| VHash | 8188af59d9cb84a352ccad89166a5c15 |
| SSDEEP | 12288:Fs+/py5fM2l+M5F7TsJwtY1yvr+bT1psS+6T6NCj76tsdh:Fs6pyCC/Ya2hpi6T6N4n |
| TLSH | T100A423B4F9219E9F6DD769B91B24831DE182C172589D4C2313AE94A34F3D732AF2CC16 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header |
| File size | 438.6 KB |
History
| First seen on VirusTotal | 2026-09-25 09:21 UTC |
| Last submission | 2026-09-25 09:21 UTC |
| Last analysis | 2026-09-25 09:21 UTC |
| Last modified on VirusTotal | 2026-09-25 11:21 UTC |
Known Names
pomwwvkk.exeuplugplayqu7wvgur.exe9fa5154073d4ce91fd659d8477b26a5f85c1259f18d950e4f3a4efa6e3452d5d.elf
hash_md5
7170e4943d7715770b43ff55b64caeb0
VT 26 / 75
IOC database
- Type
- hash_md5
- Value
7170e4943d7715770b43ff55b64caeb0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 26 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Linux.Prometei.5 |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Prometei |
| Arcabit | malicious | Trojan.Linux.Prometei.5 |
| Avast | malicious | ELF:Prometei-E [Trj] |
| AVG | malicious | ELF:Prometei-E [Trj] |
| Avira | malicious | TR/LINUX.Prometei.E |
| BitDefender | malicious | Trojan.Linux.Prometei.5 |
| ClamAV | malicious | Unix.Trojan.Prometei-10045451-0 |
| CTX | malicious | elf.trojan.prometei |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.BackDoor.Prometei.12 |
| Emsisoft | malicious | Trojan.Linux.Prometei.5 (B) |
| ESET-NOD32 | malicious | Linux/Prometei.B trojan |
| F-Secure | malicious | Trojan.TR/LINUX.Prometei.E |
| Fortinet | malicious | ELF/Prometei.12!tr |
| GData | malicious | Trojan.Linux.Prometei.5 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Prometei.c |
| Ikarus | malicious | Trojan.Linux.Prometei |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Prometei.a |
| Microsoft | malicious | Trojan:Linux/Coinminer.B |
| MicroWorld-eScan | malicious | Trojan.Linux.Prometei.5 |
| Rising | malicious | Backdoor.Prometei/Linux!1.DBE7 (CLASSIC) |
| SentinelOne | malicious | Static AI - Suspicious ELF |
| Tencent | malicious | Backdoor.Linux.Prometei.c |
| VIPRE | malicious | Trojan.Linux.Prometei.5 |
Details From VirusTotal
Basic Properties
| MD5 | 7170e4943d7715770b43ff55b64caeb0 |
| SHA-1 | 6a1b43de356b503f80f25bb8007185599355f750 |
| SHA-256 | 9fa5154073d4ce91fd659d8477b26a5f85c1259f18d950e4f3a4efa6e3452d5d |
| VHash | 8188af59d9cb84a352ccad89166a5c15 |
| SSDEEP | 12288:Fs+/py5fM2l+M5F7TsJwtY1yvr+bT1psS+6T6NCj76tsdh:Fs6pyCC/Ya2hpi6T6N4n |
| TLSH | T100A423B4F9219E9F6DD769B91B24831DE182C172589D4C2313AE94A34F3D732AF2CC16 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header |
| File size | 438.6 KB |
History
| First seen on VirusTotal | 2026-09-25 09:21 UTC |
| Last submission | 2026-09-25 09:21 UTC |
| Last analysis | 2026-09-25 09:21 UTC |
| Last modified on VirusTotal | 2026-09-25 11:21 UTC |
Known Names
pomwwvkk.exeuplugplayqu7wvgur.exe9fa5154073d4ce91fd659d8477b26a5f85c1259f18d950e4f3a4efa6e3452d5d.elf
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 449088 bytes. Tags: cowrie, elf, honeypot, Prometei, x64. Reporter: aLittleBitGrey. First seen: 2026-09-25 09:17:21.
Remediations (10)
-
web:any.run
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
-
web:boteraser.com
⚠️ Overview Prometei is a modular cryptomining botnet first discovered by Cisco Talos in July 2020, targeting Windows systems globally to mine the Monero c
-
web:github.com
This repository contains a technical analysis of the Prometei Botnet, documented in PDF format. The report examines its infection lifecycle, persistence mechanisms, lateral movement techniques, command-and-control infrastructure, incident response procedures, and defensive recommendations.
-
web:ismalicious.com
8,930 indicators of compromise attributed to the Prometei malware family — domains, IPs, URLs and file hashes, from abuse.ch feeds.
-
web:radar.offseq.com
Detailed information about ThreatFox IOCs for 2026-09-04. Get real-time updates, technical details, and mitigation strategies.
-
web:rewterz.com
Prometei Malware - Active IOCs Severity High Analysis Summary Prometei is a sophisticated modular botnet malware that was first identified in 2016, with increased activity observed since 2020.
-
web:socprime.com
Prometei is a Russia-linked botnet that compromises Windows servers, installs a persistent service, steals credentials, mines Monero, and hardens the host to block competing intruders.
-
web:unit42.paloaltonetworks.com
We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features. We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.trendmicro.com
How does Prometei insidiously operate in a compromised system? This Managed Extended Detection and Response investigation conducted with the help of Trend Vision One provides a comprehensive analysis of the inner workings of this botnet so users can stop the threat in its tracks before it inflicts damage to the system.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.