MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6ed3e4d85b44330f9e8254aec9b0055cbc51438472b366dd653201abf452bb89. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Sodinokibi


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 6ed3e4d85b44330f9e8254aec9b0055cbc51438472b366dd653201abf452bb89
SHA3-384 hash: 348352f98996eaa99e9b71951a40d9bf0f24c9fd36723a7a8541eb789145c54068292316a698f067ae1ce5d7aa6a17da
SHA1 hash: 3e5c5e9d0a456864d9ceaa83d85f8dd7f8d8b785
MD5 hash: b613bf5c41588ace64748777363d9af8
humanhash: ohio-single-friend-jersey
File name:6ed3e4d85b44330f9e8254aec9b0055cbc51438472b366dd653201abf452bb89.bin.exe
Download: download sample
Signature Sodinokibi
File size:116'224 bytes
First seen:2020-08-23 19:50:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 1e6452b349d3cbc048e72755b22f42e0 (37 x Sodinokibi)
ssdeep 1536:fT8j+u++mQ8e1lpUiTBkH6dICS4ADEeMc:Gr8e1Hw6+9M
Threatray 168 similar samples on MalwareBazaar
TLSH E7B38D07BEE05532D51301F6077B6F1A8EFFBE700526407AABE4A8C91F21591E62B727
Reporter Dashowl
Tags:Decryptor REvil Sodinokibi

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'810
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the Windows subdirectories
Creating a window
Sending a UDP request
Result
Threat name:
Detection:
malicious
Classification:
rans.evad
Score:
80 / 100
Signature
Antivirus / Scanner detection for submitted sample
Contains functionality to detect sleep reduction / modifications
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Revil
Behaviour
Behavior Graph:
Threat name:
Win32.Ransomware.REvil
Status:
Malicious
First seen:
2019-08-03 13:03:24 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Result
Malware family:
sodinokibi
Score:
  10/10
Tags:
family:sodinokibi
Behaviour
Sodinokibi family
Sodinokibi/Revil sample
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments