MB-dc4866b34ca3c7df0a48048caabfa8b4cd40b7ae385c957cb66eed4abe3db01f
high
📛 Threat Title
Prometei: dc4866b34ca3c7df0a48048caabfa8b4cd40b7ae385c957cb66eed4abe3db01f
Description
File type: elf. Size: 449082 bytes. Tags: cowrie, elf, honeypot, Prometei, x64. Reporter: aLittleBitGrey. First seen: 2026-09-25 06:17:21.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
dc4866b34ca3c7df0a48048caabfa8b4cd40b7ae385c957cb66eed4abe3db01f
IOC database
- Type
- hash_sha256
- Value
dc4866b34ca3c7df0a48048caabfa8b4cd40b7ae385c957cb66eed4abe3db01f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Prometei
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
14513f7eed22068f819842a8970469201d562e93
IOC database
- Type
- hash_sha1
- Value
14513f7eed22068f819842a8970469201d562e93- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
7c1b8553243c8b0286ddf846b5a07fbf
IOC database
- Type
- hash_md5
- Value
7c1b8553243c8b0286ddf846b5a07fbf- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 449082 bytes. Tags: cowrie, elf, honeypot, Prometei, x64. Reporter: aLittleBitGrey. First seen: 2026-09-25 06:17:21.
Remediations (10)
-
web:any.run
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
-
web:boteraser.com
⚠️ Overview Prometei is a modular cryptomining botnet first discovered by Cisco Talos in July 2020, targeting Windows systems globally to mine the Monero c
-
web:dailysecurityreview.com
The malware's continual adaptation makes detection and mitigation a challenge, even for well-defended networks. This episode offers a deep dive into Prometei's architecture, capabilities, and evolution.
-
web:github.com
This repository contains a technical analysis of the Prometei Botnet, documented in PDF format. The report examines its infection lifecycle, persistence mechanisms, lateral movement techniques, command-and-control infrastructure, incident response procedures, and defensive recommendations.
-
web:rewterz.com
Prometei Malware - Active IOCs Severity High Analysis Summary Prometei is a sophisticated modular botnet malware that was first identified in 2016, with increased activity observed since 2020.
-
web:socprime.com
Prometei is a Russia-linked botnet that compromises Windows servers, installs a persistent service, steals credentials, mines Monero, and hardens the host to block competing intruders.
-
web:unit42.paloaltonetworks.com
We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features. We identified a resurgence of the Prometei botnet's Linux variant. Our analysis tracks the activity of this cryptominer and its new features.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.securitricks.com
Prometei on Securitricks: related threat intelligence, IOCs, and MITRE context.
-
web:www.trendmicro.com
How does Prometei insidiously operate in a compromised system? This Managed Extended Detection and Response investigation conducted with the help of Trend Vision One provides a comprehensive analysis of the inner workings of this botnet so users can stop the threat in its tracks before it inflicts damage to the system.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.