Malware

Win32/Filecoder.Sodinokibi information

Malware Removal

The Win32/Filecoder.Sodinokibi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Sodinokibi virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Filecoder.Sodinokibi?


File Info:

crc32: 70E3991F
md5: 1ff591e2e37178684b73926816ea758c
name: upload_file
sha1: 5b79dd2791a817e283bc41f6ef3eff42c3b8f131
sha256: 2d73ce9f8e11bbbce1bec1147bf30ef60a6d362504fbf650b3c8a0ea6f7c4fbb
sha512: fd609855cbb4781456aba9da1455d5775b58971d1f73dc50dea277c3440b80440b73435ed151232da9709e74209f9166b4d29f97991b7bc4176845a26923dbbd
ssdeep: 1536:6njEER+AxX+zKxgjUtbWcpjSO/k6ICS4AokLdD:wm+xggtbWYamAd
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.Sodinokibi also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.10828
FireEyeGeneric.mg.1ff591e2e3717868
CAT-QuickHealTrojan.GenericRI.S7143182
McAfeeGenericRXJB-QB!1FF591E2E371
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056c36b1 )
BitDefenderGen:Variant.Fugrafa.10828
K7GWTrojan ( 0056c36b1 )
Cybereasonmalicious.2e3717
TrendMicroRansom_Sodinokibi.R069C0DH720
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Sodinokibi-7013612-0
NANO-AntivirusTrojan.Win32.Filecoder.hvwjdn
Ad-AwareGen:Variant.Fugrafa.10828
EmsisoftGen:Variant.Fugrafa.10828 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
InvinceaMal/Generic-S
McAfee-GW-EditionGenericRXJB-QB!1FF591E2E371
SophosMal/Generic-S
IkarusTrojan-Ransom.Sodinokibi
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Ransom]/Win32.Sodinokibi
MicrosoftRansom:Win32/Revil.SI!MTB
ArcabitTrojan.Fugrafa.D2A4C
GDataWin32.Trojan-Ransom.Sodinokibi.F
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3490719
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34566.eyW@ayXu2vf
ALYacGen:Variant.Fugrafa.10828
MalwarebytesRansom.Sodinokibi
PandaTrj/Genetic.gen
ESET-NOD32Win32/Filecoder.Sodinokibi
TrendMicro-HouseCallRansom_Sodinokibi.R069C0DH720
RisingTrojan.Fuery!8.EAFB (TFE:5:LKgsnobeRzN)
YandexTrojan.Filecoder!EKpMwhmu7m0
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Graftor.2A43!tr
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.101574741.susgen

How to remove Win32/Filecoder.Sodinokibi?

Win32/Filecoder.Sodinokibi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment