MB-56660e77f4a459cad5fbd534433a21912c30ba203b666ffbd2dc88c4990994e1
high
📛 Threat Title
Prometei: 56660e77f4a459cad5fbd534433a21912c30ba203b666ffbd2dc88c4990994e1
Description
File type: elf. Size: 449061 bytes. Tags: Prometei. Reporter: Hassan_Pouladi. First seen: 2026-05-15 06:49:48.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
56660e77f4a459cad5fbd534433a21912c30ba203b666ffbd2dc88c4990994e1
1 feed
IOC database
- Type
- hash_sha256
- Value
56660e77f4a459cad5fbd534433a21912c30ba203b666ffbd2dc88c4990994e1- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Prometei
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
ac63c85da66d985348cfd9860810983b8d723388
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/ac63c85da66d985348cfd9860810983b8d723388
1 feed
IOC database
- Type
- hash_sha1
- Value
ac63c85da66d985348cfd9860810983b8d723388- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/ac63c85da66d985348cfd9860810983b8d723388
hash_md5
9130ab1bda6f2184653881d812cf6f4b
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9130ab1bda6f2184653881d812cf6f4b
1 feed
IOC database
- Type
- hash_md5
- Value
9130ab1bda6f2184653881d812cf6f4b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9130ab1bda6f2184653881d812cf6f4b
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 449061 bytes. Tags: Prometei. Reporter: Hassan_Pouladi. First seen: 2026-05-15 06:49:48.
Remediations (10)
-
web:any.run
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
-
web:bazaar.abuse.ch
You are currently viewing the MalwareBazaar entry for SHA256 56660e77f4a459cad5fbd534433a21912c30ba203b666ffbd2dc88c4990994e1 . While MalwareBazaar tries to identify ...
-
web:cybersecuritynews.com
A sophisticated attack is targeting Windows Server systems using Prometei , a Russian-linked botnet that has been active since 2016. This multi-functional malware combines cryptocurrency mining, credential theft, and remote-control capabilities to maintain long-term access to compromised systems.
-
web:rewterz.com
Prometei Malware - Active IOCs Severity High Analysis Summary Prometei is a sophisticated modular botnet malware that was first identified in 2016, with increased activity observed since 2020.
-
web:securitricks.com
Description Unit 42 researchers identified a new wave of Prometei botnet attacks in March 2025. The malware, which includes Linux and Windows variants, allows remote control of compromised systems for cryptocurrency mining and credential theft. Prometei is actively developed, incorporating new modules and methods, including a backdoor for various malicious activities. It uses a domain ...
-
web:socprime.com
Prometei is a Russia-linked botnet that compromises Windows servers, installs a persistent service, steals credentials, mines Monero, and hardens the host to block competing intruders.
-
web:unit42.paloaltonetworks.com
We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features. We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features.
-
web:www.broadcom.com
Prometei botnet relies on heavy encryption (including RC4 and RSA-1024) and legitimate system tools (LOLBins) to harvest system data while masking its activities. To maintain persistence, it establishes a Windows service masquerading as "UPlugPlay" and modifies security exclusions to bypass Windows Defender and firewalls.
-
web:www.esentire.com
Learn about the Prometei botnet that gets deployed on a Windows server, including a comprehensive breakdown of Prometei's technical operations, and how organizations can stay ahead of this threat.
-
web:www.trendmicro.com
How does Prometei insidiously operate in a compromised system? This Managed Extended Detection and Response investigation conducted with the help of Trend Vision One provides a comprehensive analysis of the inner workings of this botnet so users can stop the threat in its tracks before it inflicts damage to the system.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.