s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1844769 high

📛 Threat Title

Akira: MD5 hash of a malware sample (payload) 69446d7192ce7e5737bd9f7cbc7ca74a

Category: Akira Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:48 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_md5 69446d7192ce7e5737bd9f7cbc7ca74a

IOC database

Type
hash_md5
Value
69446d7192ce7e5737bd9f7cbc7ca74a
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
MD5 hash of a malware sample (payload) attributed to Akira

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:48 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as Akira .

  • web:github.com

    IOC Package: Akira Ransomware — Case Notes ("Seven Seconds to Stop Akira ") Purpose: Indicators and incident context from a single defended-environment engagement, formatted for CTI and detection use. Malware sample is a per-victim build and may not match public corpus hashes.

  • web:mycert.org.my

    Akira threat actors were first observed deploying the Windows-specific "Megazord" ransomware, with further analysis revealing that a second payload was concurrently deployed in this attack (which was later identified as a novel variant of the Akira ESXi encryptor, "Akira_v2").

  • web:threatfox.abuse.ch

    Akira IOC: b58814c0d3e05a164e26674647f331d5 ( md5_hash ) ThreatFox IOC Database You are viewing the ThreatFox database entry for md5_hash ...

  • web:www.cisa.gov

    Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and may have connections to the defunct Conti ransomware group. Akira threat actors primarily target small- and medium-sized businesses, but have also impacted larger organizations across various sectors.

  • web:www.ibm.com

    IBM X-Force Incident Response and Threat Intelligence teams have been investigating Akira ransomware attacks since the group's emergence in March 2023. Learn more about the teams' observations.

  • web:www.microsoft.com

    This malware operates on a Ransomware- as -a-Service (RaaS) model, which allows multiple threat actors to conduct widespread attacks. Its primary method is a double-extortion strategy: threat actors first exfiltrate sensitive data from compromised networks and then deploy a payload to encrypt files on Windows devices.

  • web:www.picussecurity.com

    Learn how Akira ransomware operates in 2025 with updated CISA findings. Explore its latest TTPs, initial access methods, and actionable defense strategies.

  • web:www.sentinelone.com

    Akira Ransomware uses multi-extortion tactics and a retro-styled leak site. Learn about its negotiation processes and how to mitigate it.

  • web:www.trellix.com

    About Akira The ransomware's name likely comes from an 1988 anime movie with the same name (spoilers ahead). The movie's cyberpunk aesthetic is emulated by the ransom group on their leak site, as can be seen on the image below, courtesy of BleepingComputer. Figure 1: The Akira leak site The movie is set in Neo-Tokyo, which was built after Akira destroyed the city. In the movie, Akira ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.