SUSPICIOUS — libconscrypt_jni.so
SUSPICIOUS — libconscrypt_jni.so is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
5e8c07ceb6cdda9aa1c31771e1e4ba49a5fb4692d625482e91a9ffbd6f66bff5 - SHA-1:
eddab618459bbef45aa57e7fd05a289eeb491827 - MD5:
c3095f1d9ae6a2682bdabedf12672e79 - ssdeep:
49152:UQukgZBWeGyDhfvKhOicMAQTtHPQW03lhk:UQukgZBW6Di/5v - TLSH:
T1795A8C8714E4A9C5D1DD1948F8B56B3C9A86489F82BB15CEA5D30E2290CEFB346F0D07 - Submitted as: libconscrypt_jni.so
- File type: elf · Size: 2074928 bytes
- Verdict: suspicious (44/100)
Detections (1 of 53 engines)
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://android.googlesource.com/toolchain/llvm-project - static signal, weight 0.35, confidence 0.60
- Contacted 3 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
898 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- 85.210.196.11 GB · London · AS8075 Microsoft Limited
- 10.240.0.1
- ff02::1
- 255.255.255.255
- ff02::16
- ff02::1:ff12:3456
- ff02::2
- 91.189.91.157
- 51.132.193.104 GB · London · AS8075 Microsoft Limited UK
Dropped files
- tmp_tmp.O3wsr6jNTy -
1bd59d5a1ebbca3bee200fc2d6da776eb2eed12b5c984f1c601f1eea228c7b91
Embedded URLs
- https://android.googlesource.com/toolchain/llvm-project
Embedded domains
- openssl.org
- handshake.cc
- android.googlesource.com
Embedded IP addresses
- 85.210.196.11
- 51.132.193.104
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report