s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1844744 high

📛 Threat Title

Akira: MD5 hash of a malware sample (payload) 4e0e3ad31c0c52c1e171fd1ed6b857f0

Category: Akira Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:46 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_md5 4e0e3ad31c0c52c1e171fd1ed6b857f0

IOC database

Type
hash_md5
Value
4e0e3ad31c0c52c1e171fd1ed6b857f0
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
MD5 hash of a malware sample (payload) attributed to Akira

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:46 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Remediations (10)

  • web:attack.mitre.org

    Akira ransomware employs hybrid encryption and threading to increase the speed and efficiency of encryption and runtime arguments for tailored attacks. Notable variants include Rust-based Megazord for targeting Windows and Akira _v2 for targeting VMware ESXi servers.

  • web:blog.qualys.com

    Akira ransomware is rapidly evolving. Discover how it works, who it targets, and how to defend against it with advanced security strategies.

  • web:threatfox.abuse.ch

    Akira IOC: 1d895cf4391b817e54fb9ec9d8e65f7e ( md5_hash ) ThreatFox IOC Database You are viewing the ThreatFox database entry for md5_hash ...

  • web:threatfox.abuse.ch

    Akira IOC: b58814c0d3e05a164e26674647f331d5 ( md5_hash ) ThreatFox IOC Database You are viewing the ThreatFox database entry for md5_hash ...

  • web:www.cisa.gov

    Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and may have connections to the defunct Conti ransomware group. Akira threat actors primarily target small- and medium-sized businesses, but have also impacted larger organizations across various sectors.

  • web:www.ibm.com

    IBM X-Force Incident Response and Threat Intelligence teams have been investigating Akira ransomware attacks since the group's emergence in March 2023. Learn more about the teams' observations.

  • web:www.n-able.com

    Learn how Akira ransomware operates, including key Indicators of Compromise (IOCs), hashes, and attacker tactics to help detect and reduce risk.

  • web:www.picussecurity.com

    Learn how Akira ransomware operates in 2025 with updated CISA findings. Explore its latest TTPs, initial access methods, and actionable defense strategies.

  • web:www.sentinelone.com

    Akira Ransomware uses multi-extortion tactics and a retro-styled leak site. Learn about its negotiation processes and how to mitigate it.

  • web:www.trellix.com

    About Akira The ransomware's name likely comes from an 1988 anime movie with the same name (spoilers ahead). The movie's cyberpunk aesthetic is emulated by the ransom group on their leak site, as can be seen on the image below, courtesy of BleepingComputer. Figure 1: The Akira leak site The movie is set in Neo-Tokyo, which was built after Akira destroyed the city. In the movie, Akira ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.