Try VMRay Platform
Malicious
Classifications

Ransomware

Threat Names

Sodinokibi

Remarks (2/2)

(0x02000004): The operating system was rebooted during the analysis because the sample installed a startup script, task or application for persistence.

(0x0200003A): A task was rescheduled ahead of time to reveal dormant functionality.

General

0.80 KB total sent
5.39 KB total received
1 ports: 443
2 contacted IP addresses
1 URLs extracted
0 files downloaded
0 malicious hosts detected

DNS

1 DNS requests for 1 domains
1 nameserver contacted
0 total requests returned errors

HTTP/S

1 URLs contacted, 1 servers
1 sessions, 0.80 KB sent, 5.39 KB received
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image