s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-56660e77f4a459cad5fbd534433a21912c30ba203b666ffbd2dc88c4990994e1 high

📛 Threat Title

Prometei: 56660e77f4a459cad5fbd534433a21912c30ba203b666ffbd2dc88c4990994e1

Category: Prometei Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 449061 bytes. Tags: Prometei. Reporter: Hassan_Pouladi. First seen: 2026-05-15 06:49:48.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 56660e77f4a459cad5fbd534433a21912c30ba203b666ffbd2dc88c4990994e1 1 feed

IOC database

Type
hash_sha256
Value
56660e77f4a459cad5fbd534433a21912c30ba203b666ffbd2dc88c4990994e1
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Prometei

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 ac63c85da66d985348cfd9860810983b8d723388 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/ac63c85da66d985348cfd9860810983b8d723388
1 feed

IOC database

Type
hash_sha1
Value
ac63c85da66d985348cfd9860810983b8d723388
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/ac63c85da66d985348cfd9860810983b8d723388

hash_md5 9130ab1bda6f2184653881d812cf6f4b VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9130ab1bda6f2184653881d812cf6f4b
1 feed

IOC database

Type
hash_md5
Value
9130ab1bda6f2184653881d812cf6f4b
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9130ab1bda6f2184653881d812cf6f4b

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 449061 bytes. Tags: Prometei. Reporter: Hassan_Pouladi. First seen: 2026-05-15 06:49:48.

Remediations (10)

  • web:any.run

    Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.

  • web:bazaar.abuse.ch

    You are currently viewing the MalwareBazaar entry for SHA256 56660e77f4a459cad5fbd534433a21912c30ba203b666ffbd2dc88c4990994e1 . While MalwareBazaar tries to identify ...

  • web:cybersecuritynews.com

    A sophisticated attack is targeting Windows Server systems using Prometei , a Russian-linked botnet that has been active since 2016. This multi-functional malware combines cryptocurrency mining, credential theft, and remote-control capabilities to maintain long-term access to compromised systems.

  • web:rewterz.com

    Prometei Malware - Active IOCs Severity High Analysis Summary Prometei is a sophisticated modular botnet malware that was first identified in 2016, with increased activity observed since 2020.

  • web:securitricks.com

    Description Unit 42 researchers identified a new wave of Prometei botnet attacks in March 2025. The malware, which includes Linux and Windows variants, allows remote control of compromised systems for cryptocurrency mining and credential theft. Prometei is actively developed, incorporating new modules and methods, including a backdoor for various malicious activities. It uses a domain ...

  • web:socprime.com

    Prometei is a Russia-linked botnet that compromises Windows servers, installs a persistent service, steals credentials, mines Monero, and hardens the host to block competing intruders.

  • web:unit42.paloaltonetworks.com

    We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features. We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features.

  • web:www.broadcom.com

    Prometei botnet relies on heavy encryption (including RC4 and RSA-1024) and legitimate system tools (LOLBins) to harvest system data while masking its activities. To maintain persistence, it establishes a Windows service masquerading as "UPlugPlay" and modifies security exclusions to bypass Windows Defender and firewalls.

  • web:www.esentire.com

    Learn about the Prometei botnet that gets deployed on a Windows server, including a comprehensive breakdown of Prometei's technical operations, and how organizations can stay ahead of this threat.

  • web:www.trendmicro.com

    How does Prometei insidiously operate in a compromised system? This Managed Extended Detection and Response investigation conducted with the help of Trend Vision One provides a comprehensive analysis of the inner workings of this botnet so users can stop the threat in its tracks before it inflicts damage to the system.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.