s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1844770 high

📛 Threat Title

Akira: MD5 hash of a malware sample (payload) 7d31b4d8fa391abaf49bf2c36d33fea2

Category: Akira Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:48 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_md5 7d31b4d8fa391abaf49bf2c36d33fea2

IOC database

Type
hash_md5
Value
7d31b4d8fa391abaf49bf2c36d33fea2
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
MD5 hash of a malware sample (payload) attributed to Akira

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:48 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Remediations (10)

  • web:bazaar.abuse.ch

    MalwareBazaar MalwareBazaar is a platform from abuse.ch and Spamhaus, dedicated to sharing malware samples with the infosec community, antivirus vendors, and threat intelligence providers. Upload malware samples and explore the database for valuable intelligence. Set alerts to track newly observed malware , use APIs to seamlessly push or pull signals, and automate bulk queries. With this ...

  • web:bazaar.abuse.ch

    Using the form below, you can search for malware samples by a hash ( MD5 , SHA256, SHA1), imphash, tlsh hash , ClamAV signature, tag or malware family. Browse Database

  • web:cymulate.com

    Malicious payload delivery: The simulation sends payloads associated with Akira ransomware in a safe, controlled manner. Validation of security controls: It evaluates whether these payloads are blocked or if they penetrate existing defenses to compromise systems.

  • web:github.com

    IOC Package: Akira Ransomware — Case Notes ("Seven Seconds to Stop Akira ") Purpose: Indicators and incident context from a single defended-environment engagement, formatted for CTI and detection use. Malware sample is a per-victim build and may not match public corpus hashes.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Akira malware family including references, samples and yara signatures.

  • web:www.cisa.gov

    Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and may have connections to the defunct Conti ransomware group. Akira threat actors primarily target small- and medium-sized businesses, but have also impacted larger organizations across various sectors.

  • web:www.microsoft.com

    Akira's encryption process is configurable; for files larger than 2 MB, it operates data in blocks, while for smaller files, it encrypts only a percentage of the content, around 1693 bytes. Upon launch, itappends the . akira extension to all encrypted files and deposits a ransom note titled akira_readme.txt in every affected directory.

  • web:www.picussecurity.com

    Learn how Akira ransomware operates in 2025 with updated CISA findings. Explore its latest TTPs, initial access methods, and actionable defense strategies.

  • web:www.scribd.com

    The document reports the discovery of 17 new samples of Akira Ransomware, all sharing the same entry point and created on August 21, 2024. These samples , each sized at 1.02MB, began appearing between late September and December 2024, and are associated with specific mutexes linked to other malware . A list of MD5 hashes for the samples is also provided, along with a link to further resources.

  • web:www.sentinelone.com

    Akira Ransomware is known for its retro aesthetic that's applied to its DLS. Learn about its multi-extortion tactics, negotiation processes, and mitigation techniques.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.