s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42 high

📛 Threat Title

Akira: arm7

Category: Akira Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 1393070 bytes. Tags: Akira, elf. Reporter: abuse_ch. First seen: 2026-09-09 09:15:27.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42 VT 28 / 75

IOC database

Type
hash_sha256
Value
adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Akira

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 28 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Ransomware:Linux/Akira.A
ALYac malicious Trojan.Generic.40451970
Antiy-AVL malicious Trojan[Ransom]/Linux.Akira
Arcabit malicious Trojan.Generic.D2693F82
BitDefender malicious Trojan.Generic.40451970
ClamAV malicious Multios.Ransomware.Megazord-10021030-1
CTX malicious elf.ransomware.akira
DrWeb malicious Linux.Encoder.631
Elastic malicious Linux.Ransomware.Akira
Emsisoft malicious Trojan.Generic.40451970 (B)
ESET-NOD32 malicious Linux/Filecoder.Akira.A trojan
Fortinet malicious Linux/Filecoder_Akira.A!tr
GData malicious Trojan.Generic.40451970
Google malicious Detected
huorong malicious Ransom/Akira.e
Kaspersky malicious HEUR:Trojan-Ransom.Linux.Akira.b
Kingsoft malicious Linux.Trojan-Ransom.Akira.b
Lionic malicious Trojan.Linux.Akira.j!c
McAfeeD malicious ti!ADEF929E7C44
Microsoft malicious Ransom:Linux/Akira.A!MTB
MicroWorld-eScan malicious Trojan.Generic.40451970
Rising malicious Ransom.Akira/Linux!1.128C7 (CLASSIC)
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious Artemis!Trojan
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.NPE
Tencent malicious Ransom.Linux.Akira.cgi
VIPRE malicious Trojan.Generic.40451970

Details From VirusTotal

Basic Properties
MD5d3d636486941e411942512a20fd5b152
SHA-187c9b47aacfc8b350bff1c898c7d3b7534bff6d4
SHA-256adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
VHash3aa9ba422eee90bb237e422d49ee878f
SSDEEP24576:33Vc8rXA7SuIijC1/TtttMFlwSyi/G32mgRXM06eGZWOTX3y:3hAO+wzi42mw6TTy
TLSHT1AB552B87F4809F42CAD466BAF35D4388770217FBD1E971069D254A347BCA8AB0E3F946
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, no section header
File size1.3 MB
History
First seen on VirusTotal2026-09-01 00:20 UTC
Last submission2026-09-01 00:20 UTC
Last analysis2026-09-09 12:02 UTC
Last modified on VirusTotal2026-09-10 00:24 UTC
Known Names
  • arm7
  • y8ziomgeh.exe
  • y83i3eo5.exe
  • adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
hash_sha1 87c9b47aacfc8b350bff1c898c7d3b7534bff6d4 VT 28 / 75

IOC database

Type
hash_sha1
Value
87c9b47aacfc8b350bff1c898c7d3b7534bff6d4
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 28 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Ransomware:Linux/Akira.A
ALYac malicious Trojan.Generic.40451970
Antiy-AVL malicious Trojan[Ransom]/Linux.Akira
Arcabit malicious Trojan.Generic.D2693F82
BitDefender malicious Trojan.Generic.40451970
ClamAV malicious Multios.Ransomware.Megazord-10021030-1
CTX malicious elf.ransomware.akira
DrWeb malicious Linux.Encoder.631
Elastic malicious Linux.Ransomware.Akira
Emsisoft malicious Trojan.Generic.40451970 (B)
ESET-NOD32 malicious Linux/Filecoder.Akira.A trojan
Fortinet malicious Linux/Filecoder_Akira.A!tr
GData malicious Trojan.Generic.40451970
Google malicious Detected
huorong malicious Ransom/Akira.e
Kaspersky malicious HEUR:Trojan-Ransom.Linux.Akira.b
Kingsoft malicious Linux.Trojan-Ransom.Akira.b
Lionic malicious Trojan.Linux.Akira.j!c
McAfeeD malicious ti!ADEF929E7C44
Microsoft malicious Ransom:Linux/Akira.A!MTB
MicroWorld-eScan malicious Trojan.Generic.40451970
Rising malicious Ransom.Akira/Linux!1.128C7 (CLASSIC)
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious Artemis!Trojan
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.NPE
Tencent malicious Ransom.Linux.Akira.cgi
VIPRE malicious Trojan.Generic.40451970

Details From VirusTotal

Basic Properties
MD5d3d636486941e411942512a20fd5b152
SHA-187c9b47aacfc8b350bff1c898c7d3b7534bff6d4
SHA-256adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
VHash3aa9ba422eee90bb237e422d49ee878f
SSDEEP24576:33Vc8rXA7SuIijC1/TtttMFlwSyi/G32mgRXM06eGZWOTX3y:3hAO+wzi42mw6TTy
TLSHT1AB552B87F4809F42CAD466BAF35D4388770217FBD1E971069D254A347BCA8AB0E3F946
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, no section header
File size1.3 MB
History
First seen on VirusTotal2026-09-01 00:20 UTC
Last submission2026-09-01 00:20 UTC
Last analysis2026-09-09 12:02 UTC
Last modified on VirusTotal2026-09-10 00:24 UTC
Known Names
  • arm7
  • y8ziomgeh.exe
  • y83i3eo5.exe
  • adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
hash_md5 d3d636486941e411942512a20fd5b152 VT 28 / 75

IOC database

Type
hash_md5
Value
d3d636486941e411942512a20fd5b152
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 28 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Ransomware:Linux/Akira.A
ALYac malicious Trojan.Generic.40451970
Antiy-AVL malicious Trojan[Ransom]/Linux.Akira
Arcabit malicious Trojan.Generic.D2693F82
BitDefender malicious Trojan.Generic.40451970
ClamAV malicious Multios.Ransomware.Megazord-10021030-1
CTX malicious elf.ransomware.akira
DrWeb malicious Linux.Encoder.631
Elastic malicious Linux.Ransomware.Akira
Emsisoft malicious Trojan.Generic.40451970 (B)
ESET-NOD32 malicious Linux/Filecoder.Akira.A trojan
Fortinet malicious Linux/Filecoder_Akira.A!tr
GData malicious Trojan.Generic.40451970
Google malicious Detected
huorong malicious Ransom/Akira.e
Kaspersky malicious HEUR:Trojan-Ransom.Linux.Akira.b
Kingsoft malicious Linux.Trojan-Ransom.Akira.b
Lionic malicious Trojan.Linux.Akira.j!c
McAfeeD malicious ti!ADEF929E7C44
Microsoft malicious Ransom:Linux/Akira.A!MTB
MicroWorld-eScan malicious Trojan.Generic.40451970
Rising malicious Ransom.Akira/Linux!1.128C7 (CLASSIC)
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious Artemis!Trojan
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.NPE
Tencent malicious Ransom.Linux.Akira.cgi
VIPRE malicious Trojan.Generic.40451970

Details From VirusTotal

Basic Properties
MD5d3d636486941e411942512a20fd5b152
SHA-187c9b47aacfc8b350bff1c898c7d3b7534bff6d4
SHA-256adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
VHash3aa9ba422eee90bb237e422d49ee878f
SSDEEP24576:33Vc8rXA7SuIijC1/TtttMFlwSyi/G32mgRXM06eGZWOTX3y:3hAO+wzi42mw6TTy
TLSHT1AB552B87F4809F42CAD466BAF35D4388770217FBD1E971069D254A347BCA8AB0E3F946
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, no section header
File size1.3 MB
History
First seen on VirusTotal2026-09-01 00:20 UTC
Last submission2026-09-01 00:20 UTC
Last analysis2026-09-09 12:02 UTC
Last modified on VirusTotal2026-09-10 00:24 UTC
Known Names
  • arm7
  • y8ziomgeh.exe
  • y83i3eo5.exe
  • adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 1393070 bytes. Tags: Akira, elf. Reporter: abuse_ch. First seen: 2026-09-09 09:15:27.

Remediations (10)

  • web:dailysecurityreview.com

    Akira ransomware is exploiting CVE-2024-40766 in SonicWall SSLVPN devices again, targeting unpatched endpoints. ACSC and Rapid7 warn enterprises to patch, rotate passwords, and enforce MFA immediately.

  • web:dailysecurityreview.com

    A sharp uptick in Akira ransomware activity is exploiting SonicWall remote access infrastructure, potentially via an unpatched zero-day.

  • web:github.com

    MIT license Moreitems Ransom Busters & Akira Tactical Mitigation Patch This repository contains tactical mitigations to defend against recent behaviors exhibited by the "Ransom Busters" extortion group and Akira ransomware affiliates, as detailed in recent August 2026 threat intelligence reports.

  • web:github.com

    This repository contains tactical mitigations to defend against recent behaviors exhibited by the "Ransom Busters" extortion group and Akira ransomware affiliates, as detailed in recent August 2026 threat intelligence reports. Because these threat actors rely heavily on Living off the Land (LotL ...

  • web:securityarsenal.com

    Akira ransomware now encrypts data in under an hour. Defenders must automate detection to counter accelerated cyber attacks.

  • web:westoahu.hawaii.edu

    Mitigation The Health Sector Cybersecurity Coordination Center recommends a variety of mitigation strategies. One of the most effective mitigation strategies which could have been used for the Akira malware would be to enable multi-factor authentication, namely for VPNs [6].

  • web:www.cisa.gov

    Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and may have connections to the defunct Conti ransomware group. Akira threat actors primarily target small- and medium-sized businesses, but have also impacted larger organizations across various sectors.

  • web:www.hipaajournal.com

    A joint cybersecurity advisory has been issued by the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), The FBI, CISA, and the HHS have issued an updated advisory about Akira ransomware, following an acceleration of attacks on critical infrastructure entities.

  • web:www.linkedin.com

    Mitigation & Remediation Steps Apply Firmware Update to SonicOS 7.3.0 or Later: This version includes enhanced protections against brute-force, MFA bypass, and account lockouts.

  • web:www.sentinelone.com

    Akira Ransomware uses multi-extortion tactics and a retro-styled leak site. Learn about its negotiation processes and how to mitigate it.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.