TF-1844764
high
📛 Threat Title
Akira: MD5 hash of a malware sample (payload) a61ecd4bce5b291686756e7f1cda5c7b
Description
Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:47 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_md5
a61ecd4bce5b291686756e7f1cda5c7b
VT: VT base fetch failed: ConnectionError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/files/a61ecd4bce5b291686756e7f1cda5c7b (Caused by NameResolutionError("HTTPSConnection(host='www.virustotal.com', port=443): Failed to resolve 'www.virustotal.com' ([Errno -3] Temporary failure in name resolution)"))
IOC database
- Type
- hash_md5
- Value
a61ecd4bce5b291686756e7f1cda5c7b- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- MD5 hash of a malware sample (payload) attributed to Akira
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: ConnectionError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/files/a61ecd4bce5b291686756e7f1cda5c7b (Caused by NameResolutionError("HTTPSConnection(host='www.virustotal.com', port=443): Failed to resolve 'www.virustotal.com' ([Errno -3] Temporary failure in name resolution)"))
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:47 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.
Remediations (10)
-
web:attack.mitre.org
Akira ransomware employs hybrid encryption and threading to increase the speed and efficiency of encryption and runtime arguments for tailored attacks. Notable variants include Rust-based Megazord for targeting Windows and Akira _v2 for targeting VMware ESXi servers.
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as Akira .
-
web:bazaar.abuse.ch
Malware samples associated with tag akira MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with akira . Database Entry
-
web:github.com
This repository contains a comprehensive technical analysis of the Akira ransomware variant, conducted through deep reverse engineering using Ghidra, Frida, and x64dbg. The analysis spans 8,930+ lines of technical documentation with 69 professional diagrams covering every aspect of the malware's operation.
-
web:github.com
Contribute to rivitna/ Malware development by creating an account on GitHub.
-
web:www.cisa.gov
Analysts first identified Akira threat actors deploying the Windows-specific "Megazord" ransomware, and further investigation revealed the threat actors concurrently deployed a second payload during the attack, later identified as a novel variant of the Akira ESXi encryptor, Akira_v2.
-
web:www.n-able.com
Learn how Akira ransomware operates, including key Indicators of Compromise (IOCs), hashes, and attacker tactics to help detect and reduce risk.
-
web:www.picussecurity.com
Learn how Akira ransomware operates in 2025 with updated CISA findings. Explore its latest TTPs, initial access methods, and actionable defense strategies.
-
web:www.sentinelone.com
Akira Ransomware uses multi-extortion tactics and a retro-styled leak site. Learn about its negotiation processes and how to mitigate it.
-
web:www.trellix.com
The compilation date of the analyzed sample is the 29th of July 2023, and it is a console application. Arguments to such an application are usually shared via the command-line and do not require a graphical interface of sorts. Akira supports a number of arguments, which instruct the malware to execute certain functions. Below, the options are ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.