Sodinokibi Ransomware (Removal Solution)

What is “Sodinokibi”?

Sodinokibi ransomware exploits an Oracle WebLogic vulnerability (CVE-2019-2725)">2 to gain access to the target’s machine. Once it’s in, the malware attempts to implement itself with elevated user legal rights in order to access all files as well as resources on the system with no constraint.

Sodinokibi attempts to stay clear of contaminating computer systems from Romania, Russia, Ukraine, Belarus, Estonia, Latvia, Lithuania, Armenia, Georgia, Iran, Syria, Azerbaijan, Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, Uzbekistan most of them are formerly part of the USSR. This ransomware pressure utilizes AES and also Salsa20 algorithm">3 to encrypt individual’s data, AES is utilized to encrypt session secrets and also data that is sent to the control server, individual data are encrypted using Salsa20 security.

Sodinokibi uses an Elliptic-curve Diffie-Hellman crucial exchange algorithm to create and also proliferate encryption keys.

Once it infiltrates a device, it erases every one of the documents in the back-up folder.

Presently, the ransomware needs 0.32806964 BTC (≈ $2500) to reclaim accessibility to the encrypted documents. They declare that this quantity must be paid within four days or the ransom demand will be increased.

Ransomware familyREvil ransomware
Extensionrandom
Ransomware notereadme.txt
RansomFrom $2500 to $5000 (in Bitcoins)
Detection4Ransom.Phobos, Ransomware.Sodinokibi, Trojan.Multi
SymptomsMost of your files (photos, videos, documents) have a random extension and you can’t open it
Fix ToolSee If Your System Has Been Affected by Sodinokibi ransomware

REvil/Sodinokibi version 2.2 add a new text in wallpaper:

All of your files are encrypted! 
Find readme.txt and follow instructions* 
The final price depends on how fast you write to us. 
We also have gathered your sensitive data. 
We would share it in case you refuse to pay.

Revil wallpaper

This text asking payment is for get files back via decryption key:

The scary alert demanding from users to pay the ransom to decrypt the encoded data contains these frustrating warnings

The cryptography algorithm used by Sodinokibi is AES-256. So, if your documents got encrypted with a specific decryption key, which is totally and there are no other copies. The sad reality is that it is impossible to recover the information without the unique key available.

In case if Sodinokibi worked in online mode, it is impossible for you to gain access to the AES-256 key. It is stored on a remote server owned by the criminals who promote the Sodinokibi virus.

Do not pay for Sodinokibi!

_readme.txt file also indicates that the computer owners must get in touch with the Sodinokibi representatives during 72 hours starting from the moment of files where encrypted. On the condition of getting in touch within 72 hours users will be granted a 50% rebate, thus the ransom amount will be minimized down to $490). However, stay away from paying the ransom!

I definitely advise that you do not contact these frauds and do not pay. The one of the most real working solution to recover the lost data – just using the available backups, or use Decrypter tool.

The peculiarity of all such viruses apply a similar set of actions for generating the unique decryption key to recover the ciphered data.

Thus, unless the ransomware is still under the stage of development or possesses with some hard-to-track flaws, manually recovering the ciphered data is a thing you can’t really perform. The only solution to prevent the loss of your valuable data is to regularly make backups of your crucial files.

Note that even if you do maintain such backups regularly, they ought to be put into a specific location without loitering, not being connected to your main workstation.

For instance, the backup may be kept on the USB flash drive or some alternative external hard drive storage. Optionally, you may refer to the help of online (cloud) information storage.

Needless to mention, when you maintain your backup data on your common device, it may be similarly ciphered as well as other data.

For this reason, locating the backup on your main PC is surely not a good idea.

Marcus Vance

Marcus Vance

Cybersecurity & Digital Privacy Researcher

Marcus Vance is a cybersecurity auditor and technology writer dedicated to educating the public about online safety, data privacy regulations, enterprise security, and emerging cyber threats.

Share this article
Twitter Facebook Pinterest