SUSPICIOUS — libmediapipe_tasks_vision_jni.so
SUSPICIOUS — libmediapipe_tasks_vision_jni.so is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100), attributed to the AntiVM family. 1 of 56 detection engines flagged it.
Identification
- SHA-256:
6e81226752fbfd0da0cae41c3e8743bee25be979bb8f03003c4fe1ca70a54bb5 - SHA-1:
0f3e2f45210c98a60265b4ff4fe758cefb578f72 - MD5:
a0c5c6cf5a7984dcb8be6ef7e39d0683 - ssdeep:
98304:7MRdw543tcgG1/644iN7lgrdJz+C8/LKgsxXEhnD5LrBU14CD9:sdw543tQ1/2yRgrdd+33sGhnDVu14Y9 - TLSH:
T1D26B9DC015746906FBE89119F5E5B92D47C348CF85791ECE60F30A92A282BB345B4FA3 - Submitted as: libmediapipe_tasks_vision_jni.so
- File type: elf · Size: 10422840 bytes
- Verdict: suspicious (40/100) · Family: AntiVM
Detections (1 of 56 engines)
- YARA: Yara-Rules community: YR_AntiVM_Sandbox
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- YARA: Yara-Rules community flagged YR_AntiVM_Sandbox (rule
YR_AntiVM_Sandbox) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.tensorflow.org/lite/guide/ops_select, https://www.tensorflow.org/lite/guide/ops_custom, https://android.googlesource.com/toolchain/llvm-project - static signal, weight 0.35, confidence 0.60
Dynamic analysis
This sample is built for AArch64, which no sandbox guest in our fleet executes, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
Embedded URLs
- https://www.tensorflow.org/lite/guide/ops_select
- https://github.com/opencv/opencv/issues/16739
- https://www.tensorflow.org/lite/guide/ops_custom
- https://android.googlesource.com/toolchain/llvm-project
Embedded domains
- runtime.cc
- packet.cc
- helpers.cc
- type.googleapis.com
- div.cc
- utils.cc
- cumsum.cc
- reshape.cc
- preprocessor.cc
- add.cc
- converter.cc
- if.cc
- unpack.cc
- trmul.cc
- mfcc.cc
- pad.cc
- clock.cc
- bitcast.cc
- fill.cc
- gather.cc
- rename.cc
- buffer.cc
- subgraph.cc
- dequantize.cc
- split.cc
More AntiVM samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report