s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1844768 high

📛 Threat Title

Akira: MD5 hash of a malware sample (payload) f1e9419110b9f316c070eca39bea63d6

Category: Akira Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:48 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_md5 f1e9419110b9f316c070eca39bea63d6

IOC database

Type
hash_md5
Value
f1e9419110b9f316c070eca39bea63d6
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
MD5 hash of a malware sample (payload) attributed to Akira

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:48 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Remediations (10)

  • web:bazaar.abuse.ch

    Malware samples associated with tag akira MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with akira . Database Entry

  • web:github.com

    This repository contains a comprehensive technical analysis of the Akira ransomware variant, conducted through deep reverse engineering using Ghidra, Frida, and x64dbg. The analysis spans 8,930+ lines of technical documentation with 69 professional diagrams covering every aspect of the malware's operation.

  • web:threatfox.abuse.ch

    Akira IOC: 1d895cf4391b817e54fb9ec9d8e65f7e ( md5_hash ) ThreatFox IOC Database You are viewing the ThreatFox database entry for md5_hash ...

  • web:www.cisa.gov

    This updated joint advisory provides network defenders with the latest indicators of compromise, tactics, techniques, and procedures, and detection methods associated with Akira ransomware activity.

  • web:www.cisa.gov

    Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and may have connections to the defunct Conti ransomware group. Akira threat actors primarily target small- and medium-sized businesses, but have also impacted larger organizations across various sectors.

  • web:www.ic3.gov

    Akira threat actors were first observed deploying the Windows-specific "Megazord" ransomware, with further analysis revealing that a second payload was concurrently deployed in this attack (which was later identified as a novel variant of the Akira ESXi encryptor, "Akira_v2").

  • web:www.ic3.gov

    Summary This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ...

  • web:www.microsoft.com

    This malware operates on a Ransomware- as -a-Service (RaaS) model, which allows multiple threat actors to conduct widespread attacks. Its primary method is a double-extortion strategy: threat actors first exfiltrate sensitive data from compromised networks and then deploy a payload to encrypt files on Windows devices.

  • web:www.picussecurity.com

    Learn how Akira ransomware operates in 2025 with updated CISA findings. Explore its latest TTPs, initial access methods, and actionable defense strategies.

  • web:www.sentinelone.com

    Akira Ransomware uses multi-extortion tactics and a retro-styled leak site. Learn about its negotiation processes and how to mitigate it.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.