File name:

Akira Ransomware

Full analysis: https://app.any.run/tasks/07af3f86-c7ac-47d4-959b-e9c9b3820546
Verdict: Malicious activity
Threats:

Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.

Analysis date: November 05, 2024, 12:30:22
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
akira
ransomware
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 7 sections
MD5:

BFF3FDBFF0A5D4AA1C03F7982C968E54

SHA1:

651C70F9D995C52FA48493B2E60904D15CAD8821

SHA256:

2E2AD6392E75D5A5155498C2A76CB373D17CA3AD4BA57C6D33C623FCA5E29342

SSDEEP:

24576:mh2dD4Fk3bIz794che70h8lhddv6r970sPP8:Ok3bIz794che70h8lhddv6r970sPP8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • AKIRA has been detected (YARA)

      • Akira Ransomware.exe (PID: 4224)
  • SUSPICIOUS

    • Creates file in the systems drive root

      • Akira Ransomware.exe (PID: 4224)
  • INFO

    • Reads the machine GUID from the registry

      • Akira Ransomware.exe (PID: 4224)
    • Checks supported languages

      • Akira Ransomware.exe (PID: 4224)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:07:02 08:58:41+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.35
CodeSize: 423424
InitializedDataSize: 169472
UninitializedDataSize: -
EntryPoint: 0x35290
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
4208\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAkira Ransomware.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4224"C:\Users\admin\AppData\Local\Temp\Akira Ransomware.exe" C:\Users\admin\AppData\Local\Temp\Akira Ransomware.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\akira ransomware.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
360
Read events
331
Write events
23
Delete events
6

Modification events

(PID) Process:(4224) Akira Ransomware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
801000002116197F7E2FDB01
(PID) Process:(4224) Akira Ransomware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
B7307EDD2BC4324F9600D51AB64BD86047BF22817661986D46056E5EFADACF6F
(PID) Process:(4224) Akira Ransomware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(4224) Akira Ransomware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\ConnectedDevicesPlatform\L.admin\ActivitiesCache.db-shm
(PID) Process:(4224) Akira Ransomware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:RegFilesHash
Value:
CBC3B0F5BDD7680C56D7AB160D77D065EBEEBEE1BA33A3BB146F67FE54A7AEE4
(PID) Process:(4224) Akira Ransomware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
2
(PID) Process:(4224) Akira Ransomware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0002
Operation:writeName:Owner
Value:
801000002116197F7E2FDB01
(PID) Process:(4224) Akira Ransomware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0002
Operation:writeName:SessionHash
Value:
E619184030959E01F915284630D3D78D36EFA474365FB3B74E9F709049F4E629
(PID) Process:(4224) Akira Ransomware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0002
Operation:writeName:Sequence
Value:
1
(PID) Process:(4224) Akira Ransomware.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0002
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\ConnectedDevicesPlatform\L.admin\ActivitiesCache.db-wal
Executable files
5
Suspicious files
3 134
Text files
1 645
Unknown types
42

Dropped files

PID
Process
Filename
Type
4224Akira Ransomware.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xmlbinary
MD5:370F66E521F36A68E5A2B6379A722FB9
SHA256:BCBB387FA0D33F3475CB619963980AEB2A8F3569F69AF4F242448EE09F6BDE32
4224Akira Ransomware.exeC:\bootTel.datbinary
MD5:0FC8765F12FCA1802345386509F639D8
SHA256:920F322F7D8EF2E2D66BC1D46D521D8F6E8A6C757E5F4B620CDF5757ADC64195
4224Akira Ransomware.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\i640.cab.catbinary
MD5:7635724CF155AEFA8AE132B79489AC9D
SHA256:3223B226E23AC5D80FBFF9677BF8EA235A957F508F8762439175DB75178F9FBE
4224Akira Ransomware.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\ClientCapabilities.jsonbinary
MD5:0F1219A961D66322C2146E693D7036B4
SHA256:988675C9F441CAA919BC149364333305676E9936374419E7572424B5C3ACC063
4224Akira Ransomware.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hashbinary
MD5:24DA43B837C173EB14C3E8598245BB72
SHA256:CCA6E485E32E0299D71E20930208FB0F99E9BC7570B0BC3A3E0A17D57897EE11
4224Akira Ransomware.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\ClientEventLogMessages.manbinary
MD5:D618563954E33044D7AF0D21580A7BFA
SHA256:A9422BA82A993824E0267272558A11BE029404744DECF4196D838103DF6B99EF
4224Akira Ransomware.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\FrequentOfficeUpdateSchedule.xmlbinary
MD5:7B98E5824D10CE9BBDF79881812DA12C
SHA256:DCDA8ECA38F40A61BD8C0EE03FE62AC5C234BE71A19E01C2CE25D44E2BBE1CDA
4224Akira Ransomware.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xmlbinary
MD5:3506C258D67377C5CC7BBF40565CB004
SHA256:8AAC48FF46DCE8BAD73E9537074A1E389E3FAD678DC40967225CAA37F02C74AC
4224Akira Ransomware.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVClientIsv.manbinary
MD5:065C695278FD2A3DEB7D7D7FF05FC85C
SHA256:AA0731017154085819DBD8BE18D84CD7E367B278DB5A212C27E4B09932900251
4224Akira Ransomware.exeC:\Users\admin\.ms-ad\akira_readme.txttext
MD5:E33084005D56FF8FC2442E3096F60CA8
SHA256:FA8C0D1B8E02D6879D6AC66006DE3AD6AB365E1275958E1DA62553E67EB65C3E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
38
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
6944
svchost.exe
GET
200
23.32.185.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
BR
binary
973 b
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
314 b
whitelisted
6692
SIHClient.exe
GET
200
23.32.185.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
BR
binary
418 b
whitelisted
2076
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
6692
SIHClient.exe
GET
200
23.32.185.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
BR
binary
408 b
whitelisted
4308
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2464
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6944
svchost.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
6944
svchost.exe
23.32.185.131:80
www.microsoft.com
AKAMAI-AS
BR
whitelisted
5488
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4360
SearchApp.exe
2.23.209.186:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.9
whitelisted
www.microsoft.com
  • 23.32.185.131
whitelisted
www.bing.com
  • 2.23.209.186
  • 2.23.209.185
  • 2.23.209.183
  • 2.23.209.173
  • 2.23.209.179
  • 2.23.209.182
  • 2.23.209.189
  • 2.23.209.181
  • 2.23.209.177
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.138
  • 20.190.160.22
  • 40.126.32.134
  • 40.126.32.133
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.14
whitelisted
th.bing.com
  • 2.23.209.186
  • 2.23.209.183
  • 2.23.209.176
  • 2.23.209.180
  • 2.23.209.178
  • 2.23.209.187
  • 2.23.209.179
  • 2.23.209.182
  • 2.23.209.175
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info