Prolaco is a worm analyzed via Windows memory forensics using a memory image named prolaco.vmem. The content states that it is not a rootkit, but it has rootkit-like functionality: it can manipulate Windows kernel objects and hide its own processes by unlinking itself from kernel process structures, causing common live-response and memory-forensics tools such as Volatility/Rekall pslist and psview, Process Explorer, Process Hacker, and Windows Kernel Explorer to miss it. In the cited analysis, standard process enumeration with Volatility pslist and pstree did not show the hidden process, while psscan revealed it. One walkthrough associates a suspicious remote connection to an external IP with hidden PID 1336, which psscan identifies as process name 1_doc_RCData_61; another walkthrough highlights an unlinked process with PID 1136 in MemProcFS-assisted analysis. The content suggests the executable may be embedded in a file resource section based on the RCData-like process name, but this remains a hypothesis. The malware is discussed in the context of incident response and malware investigation on Windows XP x86 memory images, with analysts using Volatility and MemProcFS to recover process, process-tree, and command-line artifacts such as win_cmdline. High-confidence indicators from the content include the sample/memory image name prolaco.vmem, hidden process names/PIDs observed during analysis (notably 1_doc_RCData_61 / PID 1336, and PID 1136 in a separate example), and behavior involving hidden processes and suspicious outbound network connectivity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Prolaco is not a rootkit, but it does have the ability to manipulate kernel objects and hide its own processes.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm discussed as having rootkit-like stealth functionality, specifically the ability to manipulate kernel objects and hide its own processes.
Referenced as the malware sample used for the memory dump analysis example involving hidden/unlinked processes in memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.