MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5fa14751ef7fa7299d9ac8a13a45d50c91fc787e720ae661742a211861319972. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Sodinokibi


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 5fa14751ef7fa7299d9ac8a13a45d50c91fc787e720ae661742a211861319972
SHA3-384 hash: fe80252504b461ea633f57d57a1ccf862be15c44826c882cb5e41bfdfa8524425b0fe58f743a6351db6edd73fab3de8b
SHA1 hash: 39893ae4b3cbddfb8ebea174e233796e1fbed040
MD5 hash: 5421d7aac261b84a837f6958f075a022
humanhash: winner-six-mountain-tennis
File name:5fa14751ef7fa7299d9ac8a13a45d50c91fc787e720ae661742a211861319972.bin.exe
Download: download sample
Signature Sodinokibi
File size:117'248 bytes
First seen:2020-08-23 19:11:15 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 1e6452b349d3cbc048e72755b22f42e0 (37 x Sodinokibi)
ssdeep 1536:fFO1Nt+AF+2F8yZppMakhkwICS4AmFO+fP:td68yZLniOYP
Threatray 168 similar samples on MalwareBazaar
TLSH DDB37E43BFD04931D49302F506BB7F169AFEBD70052A907AAB94988D1F31D91E62B723
Reporter Dashowl
Tags:Decryptor REvil Sodinokibi

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'093
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the Windows subdirectories
Creating a window
Sending a UDP request
Result
Threat name:
Detection:
malicious
Classification:
rans.evad
Score:
80 / 100
Signature
Antivirus / Scanner detection for submitted sample
Contains functionality to detect sleep reduction / modifications
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Revil
Behaviour
Behavior Graph:
Threat name:
Win32.Ransomware.Sodinokibi
Status:
Malicious
First seen:
2020-03-12 17:19:21 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
sodinokibi
Score:
  10/10
Tags:
family:sodinokibi
Behaviour
Sodinokibi family
Sodinokibi/Revil sample
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments