Akira - The old-new style crime
Tags
Common Information
Type | Value |
---|---|
UUID | bf2b7440-3119-4bfb-ab30-8020a6a7a4b3 |
Fingerprint | 965012a92179a270 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | June 19, 2024, midnight |
Added to db | Aug. 31, 2024, 7:09 a.m. |
Last updated | Nov. 17, 2024, 6:56 p.m. |
Headline | Akira - The old-new style crime |
Title | Akira - The old-new style crime |
Detected Hints/Tags/Attributes | 67/2/115 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 208 | ✔ | RexorVc0 | https://rexorvc0.com/atom.xml | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 1 | jotuhup.com |
|
Details | Domain | 1 | zuvebeb.com |
|
Details | Domain | 1 | ceyuvigi.com |
|
Details | Domain | 1 | naporiz.com |
|
Details | Domain | 1 | xafehot.com |
|
Details | Domain | 1 | natuzujut.com |
|
Details | Domain | 1 | pucaxejun.com |
|
Details | Domain | 1 | napajep.com |
|
Details | Domain | 1 | nemucefah.com |
|
Details | Domain | 1 | jugiruturi.com |
|
Details | Domain | 1 | pijixepi.com |
|
Details | Domain | 1 | jahojahi.com |
|
Details | Domain | 1 | hakakebero.com |
|
Details | Domain | 1 | vezawahoy.com |
|
Details | Domain | 1 | sakogabu.com |
|
Details | Domain | 1 | xamayojir.com |
|
Details | Domain | 1 | tevokaxol.com |
|
Details | Domain | 2 | danimos.com |
|
Details | Domain | 1 | vosuxizen.com |
|
Details | Domain | 1 | lugociyah.com |
|
Details | Domain | 1 | duladani.com |
|
Details | Domain | 3 | bukifide.com |
|
Details | Domain | 1 | wijakezada.com |
|
Details | Domain | 1 | yuzowul.com |
|
Details | Domain | 1 | dehelibe.com |
|
Details | Domain | 1 | yavahiyil.com |
|
Details | Domain | 1 | rikukof.com |
|
Details | Domain | 1 | rabihino.com |
|
Details | Domain | 1 | talulime.com |
|
Details | Domain | 1 | repairdll.net |
|
Details | File | 1208 | powershell.exe |
|
Details | File | 2125 | cmd.exe |
|
Details | File | 26 | akira_readme.txt |
|
Details | File | 2 | help-you.txt |
|
Details | File | 69 | comsvcs.dll |
|
Details | md5 | 1 | 2CDA932F5A9DAFB0A328D0F9788BD89C |
|
Details | md5 | 1 | 64F8E1B825887AFE3130AF4BF4611C21 |
|
Details | md5 | 1 | A18D79E94229FDF02EF091CF974ED546 |
|
Details | md5 | 1 | 3F63951399F8CD578E2A6FAED2C9C0F0 |
|
Details | md5 | 1 | 4EDC0EFE1FD24F4F9EA234B83FCAEB6A |
|
Details | md5 | 1 | C2CBBD6E392A453A47DA69D086756E71 |
|
Details | md5 | 1 | 9F801240AF1124B66DEFCD4B4AE63F2A |
|
Details | md5 | 1 | FD380DB23531BB7BB610A7B32FC2A6D5 |
|
Details | md5 | 1 | BD046164DAF3C30E265D4F9C6647F630 |
|
Details | md5 | 1 | 7ca94d84f4a02fb1f608818c1c3ab62d |
|
Details | md5 | 1 | 11a6a4bfa63286feaeaf2c231ce769c3 |
|
Details | md5 | 1 | Adf426e30f8a3383c6696d2f142907d3 |
|
Details | md5 | 1 | F9a3a00b8772103ca109662b32d01934 |
|
Details | md5 | 1 | 495afbc7ebae07d50c529c1bd5889f54 |
|
Details | md5 | 1 | 491f619c358382872f87e1479c145a5e |
|
Details | md5 | 1 | 0c706908df97857255252837ac1b90c9 |
|
Details | md5 | 1 | D24cd19a50e6d574a0cfdfc07c6d22bb |
|
Details | IPv4 | 2 | 91.132.92.60 |
|
Details | IPv4 | 2 | 138.124.184.174 |
|
Details | IPv4 | 2 | 148.72.168.13 |
|
Details | IPv4 | 2 | 148.72.171.171 |
|
Details | IPv4 | 2 | 199.127.60.236 |
|
Details | IPv4 | 1 | 45.227.254.26 |
|
Details | IPv4 | 1 | 80.66.88.203 |
|
Details | IPv4 | 1 | 91.240.118.29 |
|
Details | IPv4 | 4 | 152.89.196.111 |
|
Details | IPv4 | 1 | 194.26.29.102 |
|
Details | IPv4 | 1 | 185.11.61.114 |
|
Details | IPv4 | 1 | 23.83.133.104 |
|
Details | IPv4 | 1 | 23.108.57.151 |
|
Details | IPv4 | 1 | 64.44.102.190 |
|
Details | IPv4 | 4 | 20.99.133.109 |
|
Details | IPv4 | 3 | 20.99.185.48 |
|
Details | IPv4 | 6 | 13.107.4.50 |
|
Details | IPv4 | 7 | 192.229.211.108 |
|
Details | IPv4 | 11 | 23.216.147.64 |
|
Details | IPv4 | 8 | 23.216.147.76 |
|
Details | IPv4 | 1 | 64.44.135.135 |
|
Details | IPv4 | 16 | 162.159.130.233 |
|
Details | IPv4 | 15 | 162.159.134.233 |
|
Details | IPv4 | 18 | 162.159.133.233 |
|
Details | IPv4 | 1 | 108.177.127.94 |
|
Details | IPv4 | 1 | 108.177.119.95 |
|
Details | IPv4 | 1 | 108.177.126.132 |
|
Details | IPv4 | 1 | 23.106.215.210 |
|
Details | IPv4 | 1 | 23.108.57.1 |
|
Details | IPv4 | 1 | 157.254.194.99 |
|
Details | IPv4 | 3 | 23.106.123.15 |
|
Details | IPv4 | 1 | 23.82.140.10 |
|
Details | IPv4 | 1 | 23.106.215.64 |
|
Details | IPv4 | 1 | 23.108.57.240 |
|
Details | IPv4 | 1 | 23.19.58.94 |
|
Details | IPv4 | 1 | 23.108.57.94 |
|
Details | IPv4 | 1 | 23.81.246.200 |
|
Details | IPv4 | 1 | 108.62.118.197 |
|
Details | IPv4 | 1 | 23.106.160.141 |
|
Details | IPv4 | 1 | 23.106.223.200 |
|
Details | IPv4 | 1 | 108.62.118.180 |
|
Details | IPv4 | 1 | 23.82.140.122 |
|
Details | IPv4 | 3 | 108.177.235.187 |
|
Details | IPv4 | 1 | 64.44.102.207 |
|
Details | IPv4 | 1 | 45.147.230.83 |
|
Details | IPv4 | 1 | 64.44.102.133 |
|
Details | IPv4 | 1 | 64.44.102.127 |
|
Details | IPv4 | 1 | 108.62.141.243 |
|
Details | IPv4 | 1 | 64.44.102.19 |
|
Details | IPv4 | 2 | 108.62.118.131 |
|
Details | IPv4 | 1 | 64.44.98.232 |
|
Details | IPv4 | 1 | 23.108.57.213 |
|
Details | MITRE ATT&CK Techniques | 695 | T1059 |
|
Details | MITRE ATT&CK Techniques | 159 | T1021 |
|
Details | MITRE ATT&CK Techniques | 67 | T1074 |
|
Details | MITRE ATT&CK Techniques | 276 | T1490 |
|
Details | MITRE ATT&CK Techniques | 472 | T1486 |
|
Details | MITRE ATT&CK Techniques | 86 | T1136 |
|
Details | MITRE ATT&CK Techniques | 289 | T1003 |
|
Details | MITRE ATT&CK Techniques | 179 | T1087 |
|
Details | MITRE ATT&CK Techniques | 235 | T1562 |
|
Details | Url | 1 | http://repairdll.net/jhkioeyc |
|
Details | Yara rule | 1 | rule TA_Ransomware_Akira { meta: description = "Akira: The old-new style crime" category = "Ransomware" author = "vc0rexor" reference = "" date = "2024-06-01" strings: $a1 = "expand 32-byte" ascii wide nocase $a2 = "akira" ascii nocase $a3 = "onion" ascii nocase $a4 = "TOR browser" ascii nocase fullword $a5 = "--encryption_path" ascii wide nocase $a6 = "--encryption_percent" ascii wide nocase $a7 = "CreateThread" ascii nocase fullword $a8 = "CreateIoCompletionPort" ascii nocase fullword $a9 = "AcquireSRWLockExclusive" ascii nocase fullword $a10 = "GetCurrentThreadId" ascii nocase fullword $a11 = "GetLogicalDriveStrings" ascii nocase fullword $a12 = "GetQueuedCompletionStatus" ascii nocase fullword $a13 = "encrypt" ascii nocase $a14 = "thread pool" ascii nocase fullword $a15 = "failed" ascii wide nocase $a16 = "System Volume Information" ascii nocase fullword $a17 = "Paths Finded" ascii nocase fullword $b1 = { 0F 11 45 ?? 0F 57 C9 F3 0F 7F 4D ?? 4C 63 C0 33 D2 48 8D 4D ?? E8 ?? ?? FE FF 48 8D 4D ?? 48 83 7D ?? 08 48 0F 43 4D ?? 4C 8D 45 ?? 48 83 7D ?? 10 4C 0F 43 45 ?? 8B 45 ?? 89 44 24 28 48 89 4C 24 20 44 8B 4D ?? 33 D2 33 C9 FF 15 ?? ?? ?? 00 0F 10 45 ?? 0F 11 45 ?? 0F 10 4D ?? 0F 11 4D ?? 66 0F 6F 05 ?? ?? ?? 00 F3 0F 7F 45 ?? 66 89 ?? ?? } $b2 = { 8B C7 0F 57 C0 0F 11 44 24 ?? 4C 89 74 24 ?? 4D 8B C7 4C 89 74 24 ?? 48 8D 0C 40 48 8B ?? 24 ?? } $b3 = { 48 8D ?? 27 48 83 ?? E0 48 89 ?? F8 48 89 ?? ?? ?? 8D ?? 00 20 00 00 ?? 89 ?? ?? 33 D2 41 B8 00 20 00 00 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? B9 04 01 00 00 FF 15 ?? ?? ?? 00 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 00 00 00 ?? ?? ?? ?? ?? 8D ?? ?? 66 66 66 0F 1F 84 00 00 00 00 00 } $b4 = { 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 48 83 C1 F8 } $b5 = { 48 8B 4E ?? E8 ?? ?? ?? 00 48 8D 7C 24 20 48 89 07 48 89 F9 E8 ?? ?? ?? ?? 48 8B 46 28 48 89 47 10 0F 10 46 18 0F 29 07 48 8B 0E E8 ?? ?? ?? 00 48 8D 7C 24 20 48 89 F9 E8 ?? ?? ?? ?? 48 8B 5E 08 48 8D 4B 18 E8 ?? ?? ?? ?? 48 C7 43 18 01 00 00 00 48 83 63 20 00 48 8B 46 08 48 89 07 48 8D 4C 24 20 E8 ?? ?? ?? ?? 90 48 83 C4 40 5B 5F 5E } condition: filesize > 500KB and filesize < 1100KB and (8 of ($a*) and 2 of ($b*)) and uint16(0) == 0x5a4d } |