s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1844777 high

📛 Threat Title

Akira: MD5 hash of a malware sample (payload) cb3ac44312acae80a626ba1aa593f4de

Category: Akira Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:49 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_md5 cb3ac44312acae80a626ba1aa593f4de VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/cb3ac44312acae80a626ba1aa593f4de

IOC database

Type
hash_md5
Value
cb3ac44312acae80a626ba1aa593f4de
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
MD5 hash of a malware sample (payload) attributed to Akira

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/cb3ac44312acae80a626ba1aa593f4de

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware sample (payload). IOC type: MD5 hash of a malware sample (payload). Attributed malware: Akira (aliases: REDBIKE). Confidence: 75. First seen: 2026-07-04 16:17:49 UTC. Reporter: TheRavenFile. Tags: akira, Ransomware.

Remediations (10)

  • web:any.run

    Online sandbox report for Akira Ransomware, tagged as akira , ransomware, verdict: Malicious activity

  • web:bazaar.abuse.ch

    Using the form below, you can search for malware samples by a hash ( MD5 , SHA256, SHA1), imphash, tlsh hash , ClamAV signature, tag or malware family.

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as Akira .

  • web:cymulate.com

    Malicious payload delivery: The simulation sends payloads associated with Akira ransomware in a safe, controlled manner. Validation of security controls: It evaluates whether these payloads are blocked or if they penetrate existing defenses to compromise systems.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Akira malware family including references, samples and yara signatures.

  • web:www.cisa.gov

    This updated joint advisory provides network defenders with the latest indicators of compromise, tactics, techniques, and procedures, and detection methods associated with Akira ransomware activity.

  • web:www.cisa.gov

    Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and may have connections to the defunct Conti ransomware group. Akira threat actors primarily target small- and medium-sized businesses, but have also impacted larger organizations across various sectors.

  • web:www.microsoft.com

    This malware operates on a Ransomware- as -a-Service (RaaS) model, which allows multiple threat actors to conduct widespread attacks. Its primary method is a double-extortion strategy: threat actors first exfiltrate sensitive data from compromised networks and then deploy a payload to encrypt files on Windows devices.

  • web:www.sentinelone.com

    Akira Ransomware is known for its retro aesthetic that's applied to its DLS. Learn about its multi-extortion tactics, negotiation processes, and mitigation techniques.

  • web:www.trellix.com

    About Akira The ransomware's name likely comes from an 1988 anime movie with the same name (spoilers ahead). The movie's cyberpunk aesthetic is emulated by the ransom group on their leak site, as can be seen on the image below, courtesy of BleepingComputer. Figure 1: The Akira leak site The movie is set in Neo-Tokyo, which was built after Akira destroyed the city. In the movie, Akira ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.