SUSPICIOUS — libjiagu_x86.so
SUSPICIOUS — libjiagu_x86.so is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 57 detection engines flagged it.
Identification
- SHA-256:
6ee081753f582d98d552f6fa41c832fd668fb7634f5719c2bcfeea8d856d58f8 - SHA-1:
ae09cfa2351e7ca98d3acc9d9bf7d0bb17680537 - MD5:
faa973621086d6fb8d1fe86a460db40b - ssdeep:
6144:wPr1EkhRx+WtxdxY+UHLp8SuqqoFxbPADQASoqXK34sJ0fKQkC7:CJEkLvlx9UrqHFGxbPA0tV84sJ0fH - TLSH:
T1994623629396CF31CEB2DED4DC46421D90DBADB7CA223CFC6903044C74DE92798645AA - Submitted as: libjiagu_x86.so
- File type: elf · Size: 314520 bytes
- Verdict: suspicious (35/100)
Detections (1 of 57 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (linux)
839 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- _dosvc._tcp.local
- ff02::1:3
- 72.145.35.106 IE · Dublin · AS8075 Microsoft Corporation
- 224.0.0.252
- 10.240.0.255
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- 13.69.116.108 NL · Amsterdam · AS8075 Microsoft Corporation
- 20.184.175.22 US · AS8075 MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation, US
- 91.189.91.157
- ff02::2
- ff02::16
- ff02::1:ff12:3456
Embedded IP addresses
- 72.145.35.106
- 13.69.116.108
- 20.184.175.22
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report