Is sqlite3_analyzer safe?
No antivirus engine detected this unsigned Mach-O, but an uncorroborated process-injection mapping and incompletely checked direct-IP traffic warrant caution.
All 74 antivirus engines were silent, including 16 tier-1 engines, and no curated threat-intelligence source identified the sample. However, one sandbox mapped activity to process injection and recorded multiple direct-IP contacts whose reputations were not comprehensively checked, so execution should be limited to an isolated environment pending provenance verification.
4347a8d95562a29626…ff181280eb1939Recommended next actions
Before running
Do not run it until the source and publisher can be verified independently.
If you already ran it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the developer's official site or an official app store.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines were silent, including 16 tier-1 engines, and no curated threat-intelligence source identified the sample. However, one sandbox mapped activity to process injection and recorded multiple direct-IP contacts whose reputations were not comprehensively checked, so execution should be limited to an isolated environment pending provenance verification.
The strongest evidence is the complete absence of detections across 74 antivirus engines, with 16 tier-1 engines reporting no detection. One completed sandbox run did not issue a malicious verdict, and neither external intelligence nor the inspected child produced a confirmed malware finding. Against that, the runtime record maps activity to T1055 and includes numerous direct-IP contacts. The host-reputation lookup covered only one contact, so it cannot establish that the full no complete contacted-host reputation result was available. The unsigned status and unknown child reduce confidence enough that the clean engine result is not conclusive.
What We Detected
No antivirus engine flagged the Mach-O: 0 of 74 reported it as malicious or suspicious, and 16 tier-1 engines returned no detection. Curated checks also produced no MalwareBazaar, CIRCL, or YARAify match. The executable is unsigned, so there is no verified publisher identity or historical signer record supporting its origin.
Threat Behavior
One sandbox observation mapped activity to MITRE T1055, associated with process injection, and recorded multiple direct-IP connections. The sandbox itself did not issue a malicious verdict, and the T1055 mapping does not establish the precise method or intent. Only one contacted host was inspected against the reputation cache despite many observed IPs and two URLs, so no complete host-reputation conclusion is available. One dropped child was inspected without a confirmed malicious finding, but it remains unclassified.
What To Do Now
Verify that the hash came from SQLite's official distribution channel or another trusted source before running it. If provenance cannot be confirmed, keep endpoint protection enabled and test only in an isolated environment without sensitive data or credentials.
Where this verdict could be wrong4 caveats
- The MalwareTips.Synth.ProcessInjection heuristic maps runtime evidence to T1055, an offensive technique that merits caution despite having no malicious sandbox verdict.
- The MalwareTips.Synth.DirectIpC2 heuristic cites direct connections including 23.48.162.139, 72.21.91.29, and 172.64.149.23, but the saved host cross-check inspected only one host.
- signing.signed=false for an executable file type where signing is applicable, leaving no publisher identity or signer history.
- droppedChildren.rollup reports one unknown child, so the absence of a confirmed malicious child does not establish that the child is benign.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 antivirus engines reported a detection
- 16 tier-1 engines reported no detection
- No malicious sandbox verdict
- No confirmed malicious dropped child
- No MalwareBazaar, CIRCL, or YARAify match
- Unsigned Mach-O despite signing being applicable
- One sandbox mapped activity to MITRE T1055
- Multiple direct-IP contacts with incomplete reputation coverage
- One dropped child remains unclassified
- No established publisher or signer history
Obtain this utility from SQLite's official release channel and verify its published hash if available. Keep endpoint protection enabled; otherwise, run it only in a disposable isolated environment.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 of 21 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 3MITRE ATT&CK techniques
- 9spawned processes
- 22network contacts
- 7filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
sqlite3_analyzer
4347a8d95562a29626360f7b4f4a9db97a6107624879a33cdfff181280eb1939
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
/bin/zsh
02Isolated runtime analysis - ProcessObserved
Observed process
/usr/libexec/path_helper
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
awdd-anonymous-54-fragment-3.metriclog
/var/db/awdd/staging/awdd-anonymous-54-fragment-3.metriclog
04Isolated runtime analysis - Written fileObserved
awdd-anonymous-54-fragment-4.metriclog
/var/db/awdd/staging/awdd-anonymous-54-fragment-4.metriclog
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
8.8.8.8
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
23.48.162.139
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 8.8.8.8
- 23.48.162.139
- 72.21.91.29
- 8.8.4.4
- 255.255.255.255
- 172.64.149.23
- 23.11.32.159
- 23.49.5.207
- 23.32.118.183
- 23.222.244.213
- http://ocsp.comodoca.com/MFcwVaADAgEAME4wTDBKMAkGBSsOAwIaBQAEFOsl2JD%2BJyD0HX1qwV7vds9iz6t4BBR1cacZSBm8nZ3qQUfflMRId5nTeQIRAJjBcnaqg2kI3NxbTvi9QXQ%3D
- http://ocsp.comodoca.com/MFcwVaADAgEAME4wTDBKMAkGBSsOAwIaBQAEFOsl2JD+JyD0HX1qwV7vds9iz6t4BBR1cacZSBm8nZ3qQUfflMRId5nTeQIRAJjBcnaqg2kI3NxbTvi9QXQ=
- /var/db/awdd/staging/awdd-anonymous-54-fragment-3.metriclog
- /var/db/awdd/staging/awdd-anonymous-54-fragment-4.metriclog
- /var/db/awdd/staging/awdd-primary-53-fragment-1.metriclog
- /var/db/awdd/staging/awdd-primary-53-fragment-2.metriclog
- /Users/user1/Library/Caches/com.apple.iCloudNotificationAgent/fsCachedData/7973900F-BC18-44CA-AD8B-075B63C49CDE.tmp
Files this sample writes at runtime
This file drops 1 child at runtime. None are currently flagged malicious in our cache.
- c05a346a878547756dcb…af7b47Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 0 / 74engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
0 of 74 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: sqlite3_analyzer — 4347a8d95562a29626360f7b4f4a9db97a6107624879a33cdfff181280eb1939
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — /bin/zsh
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — /usr/libexec/path_helper
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: awdd-anonymous-54-fragment-3.metriclog — /var/db/awdd/staging/awdd-anonymous-54-fragment-3.metriclog
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: awdd-anonymous-54-fragment-4.metriclog — /var/db/awdd/staging/awdd-anonymous-54-fragment-4.metriclog
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 8.8.8.8 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 23.48.162.139 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence/bin/zshThe sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence23.48.162.139 · 72.21.91.29 · 172.64.149.23
0 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- sqlite3_analyzer
- Format
- Mach-O
- Code signing
- No verified publisher
- Size
- 3.0 MB
- Last analyzed
- Sep 22, 2026, 2:45 AM UTC
4347a8d95562a29626360f7b4f4a9db97a6107624879a33cdfff181280eb1939Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't run it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the developer's official site or an official app store.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is sqlite3_analyzer safe, or is it malware?
What is sqlite3_analyzer?
How many antivirus engines detected sqlite3_analyzer?
What should I do if I already ran sqlite3_analyzer?
How do I remove sqlite3_analyzer?
What is the SHA-256 hash of sqlite3_analyzer?
How up to date is this analysis of sqlite3_analyzer?
Community
Member reviews and reports for this exact file hash.