SUSPICIOUS — libconscrypt_jni.so
SUSPICIOUS — libconscrypt_jni.so is a elf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
bf855204f96020e213bd5a06c180a5d8d93f7c3ed3f537934c57c80c3e967325 - SHA-1:
3af245e944003be5b3cda1e6ad984963715b665b - MD5:
2f1eaac1cad1011bc77f1ad1eee5a63a - ssdeep:
24576:irERelzwCvSNhoTmmm9VVR93R4FuBX1Dk4hlz:oERSzzqNYmmmfrFSu9hk4hl - TLSH:
T152559DFC86D636A3C6D819016D76C9BE1D413834B6E3268EA9C852971C5886F7F31233 - Submitted as: libconscrypt_jni.so
- File type: elf · Size: 1267644 bytes
- Verdict: suspicious (44/100)
Detections (1 of 53 engines)
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://android.googlesource.com/toolchain/llvm-project - static signal, weight 0.35, confidence 0.60
- Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
845 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- 10.240.0.1
- ff02::1
- 255.255.255.255
- ff02::16
- ff02::1:ff12:3456
- ff02::2
- 91.189.91.157
Dropped files
- tmp_tmp.jPdQeK3JDv -
eb7b4766b6b679da2c71214f63363ccbd8827b6bd16f9d3edf1ad1165dad1d17
Embedded URLs
- https://android.googlesource.com/toolchain/llvm-project
Embedded domains
- openssl.org
- handshake.cc
- android.googlesource.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report