MB-adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
high
📛 Threat Title
Akira: arm7
Description
File type: elf. Size: 1393070 bytes. Tags: Akira, elf. Reporter: abuse_ch. First seen: 2026-09-09 09:15:27.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
VT 28 / 75
IOC database
- Type
- hash_sha256
- Value
adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Akira
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 28 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Ransomware:Linux/Akira.A |
| ALYac | malicious | Trojan.Generic.40451970 |
| Antiy-AVL | malicious | Trojan[Ransom]/Linux.Akira |
| Arcabit | malicious | Trojan.Generic.D2693F82 |
| BitDefender | malicious | Trojan.Generic.40451970 |
| ClamAV | malicious | Multios.Ransomware.Megazord-10021030-1 |
| CTX | malicious | elf.ransomware.akira |
| DrWeb | malicious | Linux.Encoder.631 |
| Elastic | malicious | Linux.Ransomware.Akira |
| Emsisoft | malicious | Trojan.Generic.40451970 (B) |
| ESET-NOD32 | malicious | Linux/Filecoder.Akira.A trojan |
| Fortinet | malicious | Linux/Filecoder_Akira.A!tr |
| GData | malicious | Trojan.Generic.40451970 |
| malicious | Detected |
|
| huorong | malicious | Ransom/Akira.e |
| Kaspersky | malicious | HEUR:Trojan-Ransom.Linux.Akira.b |
| Kingsoft | malicious | Linux.Trojan-Ransom.Akira.b |
| Lionic | malicious | Trojan.Linux.Akira.j!c |
| McAfeeD | malicious | ti!ADEF929E7C44 |
| Microsoft | malicious | Ransom:Linux/Akira.A!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.40451970 |
| Rising | malicious | Ransom.Akira/Linux!1.128C7 (CLASSIC) |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | Artemis!Trojan |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Ransom.Linux.Akira.cgi |
| VIPRE | malicious | Trojan.Generic.40451970 |
Details From VirusTotal
Basic Properties
| MD5 | d3d636486941e411942512a20fd5b152 |
| SHA-1 | 87c9b47aacfc8b350bff1c898c7d3b7534bff6d4 |
| SHA-256 | adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42 |
| VHash | 3aa9ba422eee90bb237e422d49ee878f |
| SSDEEP | 24576:33Vc8rXA7SuIijC1/TtttMFlwSyi/G32mgRXM06eGZWOTX3y:3hAO+wzi42mw6TTy |
| TLSH | T1AB552B87F4809F42CAD466BAF35D4388770217FBD1E971069D254A347BCA8AB0E3F946 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, no section header |
| File size | 1.3 MB |
History
| First seen on VirusTotal | 2026-09-01 00:20 UTC |
| Last submission | 2026-09-01 00:20 UTC |
| Last analysis | 2026-09-09 12:02 UTC |
| Last modified on VirusTotal | 2026-09-10 00:24 UTC |
Known Names
arm7y8ziomgeh.exey83i3eo5.exeadef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
hash_sha1
87c9b47aacfc8b350bff1c898c7d3b7534bff6d4
VT 28 / 75
IOC database
- Type
- hash_sha1
- Value
87c9b47aacfc8b350bff1c898c7d3b7534bff6d4- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 28 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Ransomware:Linux/Akira.A |
| ALYac | malicious | Trojan.Generic.40451970 |
| Antiy-AVL | malicious | Trojan[Ransom]/Linux.Akira |
| Arcabit | malicious | Trojan.Generic.D2693F82 |
| BitDefender | malicious | Trojan.Generic.40451970 |
| ClamAV | malicious | Multios.Ransomware.Megazord-10021030-1 |
| CTX | malicious | elf.ransomware.akira |
| DrWeb | malicious | Linux.Encoder.631 |
| Elastic | malicious | Linux.Ransomware.Akira |
| Emsisoft | malicious | Trojan.Generic.40451970 (B) |
| ESET-NOD32 | malicious | Linux/Filecoder.Akira.A trojan |
| Fortinet | malicious | Linux/Filecoder_Akira.A!tr |
| GData | malicious | Trojan.Generic.40451970 |
| malicious | Detected |
|
| huorong | malicious | Ransom/Akira.e |
| Kaspersky | malicious | HEUR:Trojan-Ransom.Linux.Akira.b |
| Kingsoft | malicious | Linux.Trojan-Ransom.Akira.b |
| Lionic | malicious | Trojan.Linux.Akira.j!c |
| McAfeeD | malicious | ti!ADEF929E7C44 |
| Microsoft | malicious | Ransom:Linux/Akira.A!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.40451970 |
| Rising | malicious | Ransom.Akira/Linux!1.128C7 (CLASSIC) |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | Artemis!Trojan |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Ransom.Linux.Akira.cgi |
| VIPRE | malicious | Trojan.Generic.40451970 |
Details From VirusTotal
Basic Properties
| MD5 | d3d636486941e411942512a20fd5b152 |
| SHA-1 | 87c9b47aacfc8b350bff1c898c7d3b7534bff6d4 |
| SHA-256 | adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42 |
| VHash | 3aa9ba422eee90bb237e422d49ee878f |
| SSDEEP | 24576:33Vc8rXA7SuIijC1/TtttMFlwSyi/G32mgRXM06eGZWOTX3y:3hAO+wzi42mw6TTy |
| TLSH | T1AB552B87F4809F42CAD466BAF35D4388770217FBD1E971069D254A347BCA8AB0E3F946 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, no section header |
| File size | 1.3 MB |
History
| First seen on VirusTotal | 2026-09-01 00:20 UTC |
| Last submission | 2026-09-01 00:20 UTC |
| Last analysis | 2026-09-09 12:02 UTC |
| Last modified on VirusTotal | 2026-09-10 00:24 UTC |
Known Names
arm7y8ziomgeh.exey83i3eo5.exeadef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
hash_md5
d3d636486941e411942512a20fd5b152
VT 28 / 75
IOC database
- Type
- hash_md5
- Value
d3d636486941e411942512a20fd5b152- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 28 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Ransomware:Linux/Akira.A |
| ALYac | malicious | Trojan.Generic.40451970 |
| Antiy-AVL | malicious | Trojan[Ransom]/Linux.Akira |
| Arcabit | malicious | Trojan.Generic.D2693F82 |
| BitDefender | malicious | Trojan.Generic.40451970 |
| ClamAV | malicious | Multios.Ransomware.Megazord-10021030-1 |
| CTX | malicious | elf.ransomware.akira |
| DrWeb | malicious | Linux.Encoder.631 |
| Elastic | malicious | Linux.Ransomware.Akira |
| Emsisoft | malicious | Trojan.Generic.40451970 (B) |
| ESET-NOD32 | malicious | Linux/Filecoder.Akira.A trojan |
| Fortinet | malicious | Linux/Filecoder_Akira.A!tr |
| GData | malicious | Trojan.Generic.40451970 |
| malicious | Detected |
|
| huorong | malicious | Ransom/Akira.e |
| Kaspersky | malicious | HEUR:Trojan-Ransom.Linux.Akira.b |
| Kingsoft | malicious | Linux.Trojan-Ransom.Akira.b |
| Lionic | malicious | Trojan.Linux.Akira.j!c |
| McAfeeD | malicious | ti!ADEF929E7C44 |
| Microsoft | malicious | Ransom:Linux/Akira.A!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.40451970 |
| Rising | malicious | Ransom.Akira/Linux!1.128C7 (CLASSIC) |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | Artemis!Trojan |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Ransom.Linux.Akira.cgi |
| VIPRE | malicious | Trojan.Generic.40451970 |
Details From VirusTotal
Basic Properties
| MD5 | d3d636486941e411942512a20fd5b152 |
| SHA-1 | 87c9b47aacfc8b350bff1c898c7d3b7534bff6d4 |
| SHA-256 | adef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42 |
| VHash | 3aa9ba422eee90bb237e422d49ee878f |
| SSDEEP | 24576:33Vc8rXA7SuIijC1/TtttMFlwSyi/G32mgRXM06eGZWOTX3y:3hAO+wzi42mw6TTy |
| TLSH | T1AB552B87F4809F42CAD466BAF35D4388770217FBD1E971069D254A347BCA8AB0E3F946 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, no section header |
| File size | 1.3 MB |
History
| First seen on VirusTotal | 2026-09-01 00:20 UTC |
| Last submission | 2026-09-01 00:20 UTC |
| Last analysis | 2026-09-09 12:02 UTC |
| Last modified on VirusTotal | 2026-09-10 00:24 UTC |
Known Names
arm7y8ziomgeh.exey83i3eo5.exeadef929e7c44596ed1cb4c1300826874fc48d6adc9edde45f0cfa45e9792ef42
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 1393070 bytes. Tags: Akira, elf. Reporter: abuse_ch. First seen: 2026-09-09 09:15:27.
Remediations (10)
-
web:dailysecurityreview.com
Akira ransomware is exploiting CVE-2024-40766 in SonicWall SSLVPN devices again, targeting unpatched endpoints. ACSC and Rapid7 warn enterprises to patch, rotate passwords, and enforce MFA immediately.
-
web:dailysecurityreview.com
A sharp uptick in Akira ransomware activity is exploiting SonicWall remote access infrastructure, potentially via an unpatched zero-day.
-
web:github.com
MIT license Moreitems Ransom Busters & Akira Tactical Mitigation Patch This repository contains tactical mitigations to defend against recent behaviors exhibited by the "Ransom Busters" extortion group and Akira ransomware affiliates, as detailed in recent August 2026 threat intelligence reports.
-
web:github.com
This repository contains tactical mitigations to defend against recent behaviors exhibited by the "Ransom Busters" extortion group and Akira ransomware affiliates, as detailed in recent August 2026 threat intelligence reports. Because these threat actors rely heavily on Living off the Land (LotL ...
-
web:securityarsenal.com
Akira ransomware now encrypts data in under an hour. Defenders must automate detection to counter accelerated cyber attacks.
-
web:westoahu.hawaii.edu
Mitigation The Health Sector Cybersecurity Coordination Center recommends a variety of mitigation strategies. One of the most effective mitigation strategies which could have been used for the Akira malware would be to enable multi-factor authentication, namely for VPNs [6].
-
web:www.cisa.gov
Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and may have connections to the defunct Conti ransomware group. Akira threat actors primarily target small- and medium-sized businesses, but have also impacted larger organizations across various sectors.
-
web:www.hipaajournal.com
A joint cybersecurity advisory has been issued by the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), The FBI, CISA, and the HHS have issued an updated advisory about Akira ransomware, following an acceleration of attacks on critical infrastructure entities.
-
web:www.linkedin.com
Mitigation & Remediation Steps Apply Firmware Update to SonicOS 7.3.0 or Later: This version includes enhanced protections against brute-force, MFA bypass, and account lockouts.
-
web:www.sentinelone.com
Akira Ransomware uses multi-extortion tactics and a retro-styled leak site. Learn about its negotiation processes and how to mitigate it.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.