s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1844743 high

📛 Threat Title

Akira: MD5 hash of a malware sample (payload) c1497cc6759e5c9f0e3a86d40b601559

Category: Akira Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:46 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_md5 c1497cc6759e5c9f0e3a86d40b601559

IOC database

Type
hash_md5
Value
c1497cc6759e5c9f0e3a86d40b601559
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
MD5 hash of a malware sample (payload) attributed to Akira

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:46 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Remediations (10)

  • web:bazaar.abuse.ch

    Using the form below, you can search for malware samples by a hash ( MD5 , SHA256, SHA1), imphash, tlsh hash , ClamAV signature, tag or malware family.

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as Akira .

  • web:cymulate.com

    Malicious payload delivery: The simulation sends payloads associated with Akira ransomware in a safe, controlled manner. Validation of security controls: It evaluates whether these payloads are blocked or if they penetrate existing defenses to compromise systems.

  • web:github.com

    This repository contains a comprehensive technical analysis of the Akira ransomware variant, conducted through deep reverse engineering using Ghidra, Frida, and x64dbg. The analysis spans 8,930+ lines of technical documentation with 69 professional diagrams covering every aspect of the malware's operation.

  • web:github.com

    IOC Package: Akira Ransomware — Case Notes ("Seven Seconds to Stop Akira ") Purpose: Indicators and incident context from a single defended-environment engagement, formatted for CTI and detection use. Malware sample is a per-victim build and may not match public corpus hashes.

  • web:www.cisa.gov

    Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and may have connections to the defunct Conti ransomware group. Akira threat actors primarily target small- and medium-sized businesses, but have also impacted larger organizations across various sectors.

  • web:www.microsoft.com

    This malware operates on a Ransomware- as -a-Service (RaaS) model, which allows multiple threat actors to conduct widespread attacks. Its primary method is a double-extortion strategy: threat actors first exfiltrate sensitive data from compromised networks and then deploy a payload to encrypt files on Windows devices.

  • web:www.picussecurity.com

    Learn how Akira ransomware operates in 2025 with updated CISA findings. Explore its latest TTPs, initial access methods, and actionable defense strategies.

  • web:www.scribd.com

    The document reports the discovery of 17 new samples of Akira Ransomware, all sharing the same entry point and created on August 21, 2024. These samples , each sized at 1.02MB, began appearing between late September and December 2024, and are associated with specific mutexes linked to other malware . A list of MD5 hashes for the samples is also provided, along with a link to further resources.

  • web:www.sentinelone.com

    Akira Ransomware is known for its retro aesthetic that's applied to its DLS. Learn about its multi-extortion tactics, negotiation processes, and mitigation techniques.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.