SUSPICIOUS — libsqlcipher.so
SUSPICIOUS — libsqlcipher.so is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (49/100), attributed to the mimban family. 1 of 56 detection engines flagged it.
Identification
- SHA-256:
7fb1c2e1205b7b923bb8e8edfc9792416a3dbda306bc9238df56389d57f5007b - SHA-1:
cd43fc429aff37aefe39d3ac6464cd28ab6a0f5c - MD5:
e51048a6576d5778315019ec70fe8e15 - ssdeep:
24576:RdPyeRuafn1ibC/U8Wp64lFuAwefjDI1yXgVFNQZ2O/QyHnxknSb1l57qSL46l8:vyeRuasbCmbVgqpknSb1ncjPn6b7 - TLSH:
T18E5C9D39AFA53916E59442C1CCB08D3D128D79685EFDEFDC8BC99EA3C08A8571C30199 - Submitted as: libsqlcipher.so
- File type: elf · Size: 2394580 bytes
- Verdict: suspicious (49/100) · Family: mimban
Detections (1 of 56 engines)
- YARA: ESET research: mimban
Why this verdict
The suspicious score of 49/100 is the fusion of 1 weighted signal:
- YARA: ESET research flagged mimban (rule
mimban) - engine signal, weight 0.70, confidence 0.70
Dynamic analysis
This sample is built for ARM, which no sandbox guest in our fleet executes, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
Embedded URLs
- https://www.openssl.org/docs/faq.html
Embedded domains
- www.openssl.org
More mimban samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report