MALICIOUS — libmavupdate.so
MALICIOUS — libmavupdate.so is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (81/100), attributed to the coruscant family. 3 of 57 detection engines flagged it.
Identification
- SHA-256:
a5aceb57c5372195dfcbd0e8cd0a5277bf5e20def49fdbbc1ab722a717fc9ae3 - SHA-1:
3f81e3a38f2c4882a05500fdf709a66e6f8b2c09 - MD5:
e5641c9b53fd8725a2eb5e49595b666c - ssdeep:
49152:XzopVVjjSAJR3wDrBaFqdcqlTGzrmN4PP1:kpVdeAiJcVzrmNi - TLSH:
T1B1594D33AB2A601AE52886C58C90463D22CE705C8F98DEDDCFCE4EA7540ED631D766D1 - Submitted as: libmavupdate.so
- File type: elf · Size: 1806976 bytes
- Verdict: malicious (81/100) · Family: coruscant
Detections (3 of 57 engines)
- YARA: ESET research: coruscant
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
- Microsoft Defender: flagged
Why this verdict
The malicious score of 81/100 is the fusion of 3 weighted signals:
- YARA: ESET research flagged coruscant (rule
coruscant) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.45, confidence 0.70
Dynamic analysis
This sample is built for ARM, which no sandbox guest in our fleet executes, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
Embedded domains
- www.di-mgt.com.au
- example.com
More coruscant samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report