s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-dc4866b34ca3c7df0a48048caabfa8b4cd40b7ae385c957cb66eed4abe3db01f high

📛 Threat Title

Prometei: dc4866b34ca3c7df0a48048caabfa8b4cd40b7ae385c957cb66eed4abe3db01f

Category: Prometei Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 449082 bytes. Tags: cowrie, elf, honeypot, Prometei, x64. Reporter: aLittleBitGrey. First seen: 2026-09-25 06:17:21.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 dc4866b34ca3c7df0a48048caabfa8b4cd40b7ae385c957cb66eed4abe3db01f

IOC database

Type
hash_sha256
Value
dc4866b34ca3c7df0a48048caabfa8b4cd40b7ae385c957cb66eed4abe3db01f
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Prometei

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 14513f7eed22068f819842a8970469201d562e93

IOC database

Type
hash_sha1
Value
14513f7eed22068f819842a8970469201d562e93
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 7c1b8553243c8b0286ddf846b5a07fbf

IOC database

Type
hash_md5
Value
7c1b8553243c8b0286ddf846b5a07fbf
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 449082 bytes. Tags: cowrie, elf, honeypot, Prometei, x64. Reporter: aLittleBitGrey. First seen: 2026-09-25 06:17:21.

Remediations (10)

  • web:any.run

    Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.

  • web:boteraser.com

    ⚠️ Overview Prometei is a modular cryptomining botnet first discovered by Cisco Talos in July 2020, targeting Windows systems globally to mine the Monero c

  • web:dailysecurityreview.com

    The malware's continual adaptation makes detection and mitigation a challenge, even for well-defended networks. This episode offers a deep dive into Prometei's architecture, capabilities, and evolution.

  • web:github.com

    This repository contains a technical analysis of the Prometei Botnet, documented in PDF format. The report examines its infection lifecycle, persistence mechanisms, lateral movement techniques, command-and-control infrastructure, incident response procedures, and defensive recommendations.

  • web:rewterz.com

    Prometei Malware - Active IOCs Severity High Analysis Summary Prometei is a sophisticated modular botnet malware that was first identified in 2016, with increased activity observed since 2020.

  • web:socprime.com

    Prometei is a Russia-linked botnet that compromises Windows servers, installs a persistent service, steals credentials, mines Monero, and hardens the host to block competing intruders.

  • web:unit42.paloaltonetworks.com

    We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features. We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.securitricks.com

    Prometei on Securitricks: related threat intelligence, IOCs, and MITRE context.

  • web:www.trendmicro.com

    How does Prometei insidiously operate in a compromised system? This Managed Extended Detection and Response investigation conducted with the help of Trend Vision One provides a comprehensive analysis of the inner workings of this botnet so users can stop the threat in its tracks before it inflicts damage to the system.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.