Malware

What is “Win32/Filecoder.Sodinokibi.B”?

Malware Removal

The Win32/Filecoder.Sodinokibi.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Sodinokibi.B virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • A scripting utility was executed
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Anomalous binary characteristics

How to determine Win32/Filecoder.Sodinokibi.B?


File Info:

crc32: 669F3C2B
md5: fbc303f83384605696257d0127da6104
name: tmp94r9xvlz
sha1: 75abc30df610a2815974c1249b0211b8eb8a0f2b
sha256: 48d30da58824b0efc04cc6a0b8287666e57a6d898e084225a4290e629afe5772
sha512: 3f0a5955a79935edcfcbfb22845e29240d3b74762239a9f9c6134e5bde9f390c9b8595c76f4a6913dd1ee16a969a608243e3f855ba055992de767eae8dfe0ecf
ssdeep: 1536:ck8UL5PbQCu5Nn/HDM5Oo0mjSpUCBMdqICS4AeNf1Z86KLxk3AEzi2/j:eVvpXmjmYdJ4Z1b8k3AGbj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.Sodinokibi.B also known as:

BkavW32.AIDetectVM.malwareB
DrWebTrojan.Encoder.28004
ClamAVWin.Ransomware.Sodinokibi-7013612-0
FireEyeGeneric.mg.fbc303f833846056
McAfeeRansom-Sodnkibi!FBC303F83384
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.14505
K7AntiVirusTrojan ( 0054d99c1 )
K7GWTrojan ( 0054d99c1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitDeepScan:Generic.Ransom.Sodinokibi.FE9FF902
Invinceaheuristic
BitDefenderThetaAI:Packer.59A870CF1E
F-ProtW32/Kryptik.AKW.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallRansom.Win32.SODINOKIB.SMTH
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Gen.gen
BitDefenderDeepScan:Generic.Ransom.Sodinokibi.FE9FF902
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanDeepScan:Generic.Ransom.Sodinokibi.FE9FF902
RisingRansom.Sodin!8.10CD8 (RDMK:cmRtazp0Tu7Mk9oeOrqLlQ3nZ74z)
Endgamemalicious (high confidence)
EmsisoftDeepScan:Generic.Ransom.Sodinokibi.FE9FF902 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
TrendMicroRansom.Win32.SODINOKIB.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminesuspicious.low.ml.score
IkarusTrojan-Ransom.Sodinokibi
CyrenW32/Kryptik.AKW.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Ransom]/Win32.Gen
MicrosoftTrojan:Win32/Wacatac.D!ml
ZoneAlarmHEUR:Trojan-Ransom.Win32.Gen.gen
GDataDeepScan:Generic.Ransom.Sodinokibi.FE9FF902
AhnLab-V3Trojan/Win32.RL_Ransom.R290570
Acronissuspicious
VBA32BScope.Trojan.DelShad
ALYacDeepScan:Generic.Ransom.Sodinokibi.FE9FF902
Ad-AwareDeepScan:Generic.Ransom.Sodinokibi.FE9FF902
MalwarebytesRansom.Sodinokibi
APEXMalicious
ESET-NOD32a variant of Win32/Filecoder.Sodinokibi.B
TencentMalware.Win32.Gencirc.10cdd51f
YandexTrojan.Filecoder!D4ko3vclm2c
SentinelOneDFI – Malicious PE
FortinetW32/Sodinokibi.B!tr.ransom
AVGWin32:Malware-gen
PandaTrj/GdSda.A
Qihoo-360HEUR/QVM20.1.F20B.Malware.Gen

How to remove Win32/Filecoder.Sodinokibi.B?

Win32/Filecoder.Sodinokibi.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment