MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81878c4cd8c79fcc10478f15ea6d00a0d1151a205943eaf47e8c4cd450db0915. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 81878c4cd8c79fcc10478f15ea6d00a0d1151a205943eaf47e8c4cd450db0915
SHA3-384 hash: aff5bca806a38343e280af51417444a3dbf9b9375d3b2c0f0ed53ab9c49ade77ab30e57ecf49e42d13b67d27e43541bb
SHA1 hash: 86d80dab5e2118c37b3136776e0c8150af84a879
MD5 hash: bb2d90742e11af820f0d9f5cd3d1a520
humanhash: mike-vegan-wyoming-yellow
File name:81878c4cd8c79fcc10478f15ea6d00a0d1151a205943eaf47e8c4cd450db0915.bin
Download: download sample
File size:114'176 bytes
First seen:2020-08-23 18:36:53 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 1da9bd2a660139c2d8ce0baa10e11ec5 (9 x Sodinokibi)
ssdeep 1536:p5kbYr+uk+UZgn9lpHSzlkOICS4AR3Ah:MbYrMgn9HdL3Ah
Threatray 168 similar samples on MalwareBazaar
TLSH 64B39E0FBE604131E55302FA132B2F168FFEBEB04038D47AA79449491F7719DA62B667
Reporter Dashowl
Tags:Decryptor REvil Sodinokibi

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'038
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the Windows subdirectories
Creating a window
Sending a UDP request
Result
Threat name:
Detection:
malicious
Classification:
rans.evad
Score:
80 / 100
Signature
Antivirus / Scanner detection for submitted sample
Contains functionality to detect sleep reduction / modifications
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Revil
Behaviour
Behavior Graph:
Threat name:
Win32.Ransomware.Sodinokibi
Status:
Malicious
First seen:
2019-06-16 00:41:36 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
sodinokibi
Score:
  10/10
Tags:
family:sodinokibi
Behaviour
Sodinokibi family
Sodinokibi/Revil sample
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments