Oracle first patched the issue on April 26, outside of their normal patch cycle, and assigned it CVE-2019-2725. Sodinokibi attempts to encrypt data in a user’s directory and delete shadow copy backups to make data recovery more difficult. Attackers have been making use of this exploit in the wild since at least April 17. Cisco’s Incident Response (IR) team, along with Cisco Talos, are actively investigating these attacks. The ransom note directs victims to either a website on the Toronion network or a decryptor[top]”]
Source: https://blog.talosintelligence.com/2019/04/sodinokibi-ransomware-exploits-weblogic.html