Akira - The old-new style crime
Common Information
Type Value
UUID bf2b7440-3119-4bfb-ab30-8020a6a7a4b3
Fingerprint 965012a92179a270
Analysis status DONE
Considered CTI value 2
Text language
Published June 19, 2024, midnight
Added to db Aug. 31, 2024, 7:09 a.m.
Last updated Nov. 17, 2024, 6:56 p.m.
Headline Akira - The old-new style crime
Title Akira - The old-new style crime
Detected Hints/Tags/Attributes 67/2/115
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 208 RexorVc0 https://rexorvc0.com/atom.xml 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 1
jotuhup.com
Details Domain 1
zuvebeb.com
Details Domain 1
ceyuvigi.com
Details Domain 1
naporiz.com
Details Domain 1
xafehot.com
Details Domain 1
natuzujut.com
Details Domain 1
pucaxejun.com
Details Domain 1
napajep.com
Details Domain 1
nemucefah.com
Details Domain 1
jugiruturi.com
Details Domain 1
pijixepi.com
Details Domain 1
jahojahi.com
Details Domain 1
hakakebero.com
Details Domain 1
vezawahoy.com
Details Domain 1
sakogabu.com
Details Domain 1
xamayojir.com
Details Domain 1
tevokaxol.com
Details Domain 2
danimos.com
Details Domain 1
vosuxizen.com
Details Domain 1
lugociyah.com
Details Domain 1
duladani.com
Details Domain 3
bukifide.com
Details Domain 1
wijakezada.com
Details Domain 1
yuzowul.com
Details Domain 1
dehelibe.com
Details Domain 1
yavahiyil.com
Details Domain 1
rikukof.com
Details Domain 1
rabihino.com
Details Domain 1
talulime.com
Details Domain 1
repairdll.net
Details File 1208
powershell.exe
Details File 2125
cmd.exe
Details File 26
akira_readme.txt
Details File 2
help-you.txt
Details File 69
comsvcs.dll
Details md5 1
2CDA932F5A9DAFB0A328D0F9788BD89C
Details md5 1
64F8E1B825887AFE3130AF4BF4611C21
Details md5 1
A18D79E94229FDF02EF091CF974ED546
Details md5 1
3F63951399F8CD578E2A6FAED2C9C0F0
Details md5 1
4EDC0EFE1FD24F4F9EA234B83FCAEB6A
Details md5 1
C2CBBD6E392A453A47DA69D086756E71
Details md5 1
9F801240AF1124B66DEFCD4B4AE63F2A
Details md5 1
FD380DB23531BB7BB610A7B32FC2A6D5
Details md5 1
BD046164DAF3C30E265D4F9C6647F630
Details md5 1
7ca94d84f4a02fb1f608818c1c3ab62d
Details md5 1
11a6a4bfa63286feaeaf2c231ce769c3
Details md5 1
Adf426e30f8a3383c6696d2f142907d3
Details md5 1
F9a3a00b8772103ca109662b32d01934
Details md5 1
495afbc7ebae07d50c529c1bd5889f54
Details md5 1
491f619c358382872f87e1479c145a5e
Details md5 1
0c706908df97857255252837ac1b90c9
Details md5 1
D24cd19a50e6d574a0cfdfc07c6d22bb
Details IPv4 2
91.132.92.60
Details IPv4 2
138.124.184.174
Details IPv4 2
148.72.168.13
Details IPv4 2
148.72.171.171
Details IPv4 2
199.127.60.236
Details IPv4 1
45.227.254.26
Details IPv4 1
80.66.88.203
Details IPv4 1
91.240.118.29
Details IPv4 4
152.89.196.111
Details IPv4 1
194.26.29.102
Details IPv4 1
185.11.61.114
Details IPv4 1
23.83.133.104
Details IPv4 1
23.108.57.151
Details IPv4 1
64.44.102.190
Details IPv4 4
20.99.133.109
Details IPv4 3
20.99.185.48
Details IPv4 6
13.107.4.50
Details IPv4 7
192.229.211.108
Details IPv4 11
23.216.147.64
Details IPv4 8
23.216.147.76
Details IPv4 1
64.44.135.135
Details IPv4 16
162.159.130.233
Details IPv4 15
162.159.134.233
Details IPv4 18
162.159.133.233
Details IPv4 1
108.177.127.94
Details IPv4 1
108.177.119.95
Details IPv4 1
108.177.126.132
Details IPv4 1
23.106.215.210
Details IPv4 1
23.108.57.1
Details IPv4 1
157.254.194.99
Details IPv4 3
23.106.123.15
Details IPv4 1
23.82.140.10
Details IPv4 1
23.106.215.64
Details IPv4 1
23.108.57.240
Details IPv4 1
23.19.58.94
Details IPv4 1
23.108.57.94
Details IPv4 1
23.81.246.200
Details IPv4 1
108.62.118.197
Details IPv4 1
23.106.160.141
Details IPv4 1
23.106.223.200
Details IPv4 1
108.62.118.180
Details IPv4 1
23.82.140.122
Details IPv4 3
108.177.235.187
Details IPv4 1
64.44.102.207
Details IPv4 1
45.147.230.83
Details IPv4 1
64.44.102.133
Details IPv4 1
64.44.102.127
Details IPv4 1
108.62.141.243
Details IPv4 1
64.44.102.19
Details IPv4 2
108.62.118.131
Details IPv4 1
64.44.98.232
Details IPv4 1
23.108.57.213
Details MITRE ATT&CK Techniques 695
T1059
Details MITRE ATT&CK Techniques 159
T1021
Details MITRE ATT&CK Techniques 67
T1074
Details MITRE ATT&CK Techniques 276
T1490
Details MITRE ATT&CK Techniques 472
T1486
Details MITRE ATT&CK Techniques 86
T1136
Details MITRE ATT&CK Techniques 289
T1003
Details MITRE ATT&CK Techniques 179
T1087
Details MITRE ATT&CK Techniques 235
T1562
Details Url 1
http://repairdll.net/jhkioeyc
Details Yara rule 1
rule TA_Ransomware_Akira {
	meta:
		description = "Akira: The old-new style crime"
		category = "Ransomware"
		author = "vc0rexor"
		reference = ""
		date = "2024-06-01"
	strings:
		$a1 = "expand 32-byte" ascii wide nocase
		$a2 = "akira" ascii nocase
		$a3 = "onion" ascii nocase
		$a4 = "TOR browser" ascii nocase fullword
		$a5 = "--encryption_path" ascii wide nocase
		$a6 = "--encryption_percent" ascii wide nocase
		$a7 = "CreateThread" ascii nocase fullword
		$a8 = "CreateIoCompletionPort" ascii nocase fullword
		$a9 = "AcquireSRWLockExclusive" ascii nocase fullword
		$a10 = "GetCurrentThreadId" ascii nocase fullword
		$a11 = "GetLogicalDriveStrings" ascii nocase fullword
		$a12 = "GetQueuedCompletionStatus" ascii nocase fullword
		$a13 = "encrypt" ascii nocase
		$a14 = "thread pool" ascii nocase fullword
		$a15 = "failed" ascii wide nocase
		$a16 = "System Volume Information" ascii nocase fullword
		$a17 = "Paths Finded" ascii nocase fullword
		$b1 = { 0F 11 45 ?? 0F 57 C9 F3 0F 7F 4D ?? 4C 63 C0 33 D2 48 8D 4D ?? E8 ?? ?? FE FF 48 8D 4D ?? 48 83 7D ?? 08 48 0F 43 4D ?? 4C 8D 45 ?? 48 83 7D ?? 10 4C 0F 43 45 ?? 8B 45 ?? 89 44 24 28 48 89 4C 24 20 44 8B 4D ?? 33 D2 33 C9 FF 15 ?? ?? ?? 00 0F 10 45 ?? 0F 11 45 ?? 0F 10 4D ?? 0F 11 4D ?? 66 0F 6F 05 ?? ?? ?? 00 F3 0F 7F 45 ?? 66 89 ?? ?? }
		$b2 = { 8B C7 0F 57 C0 0F 11 44 24 ?? 4C 89 74 24 ?? 4D 8B C7 4C 89 74 24 ?? 48 8D 0C 40 48 8B ?? 24 ?? }
		$b3 = { 48 8D ?? 27 48 83 ?? E0 48 89 ?? F8 48 89 ?? ?? ?? 8D ?? 00 20 00 00 ?? 89 ?? ?? 33 D2 41 B8 00 20 00 00 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? B9 04 01 00 00 FF 15 ?? ?? ?? 00 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 00 00 00 ?? ?? ?? ?? ?? 8D ?? ?? 66 66 66 0F 1F 84 00 00 00 00 00 }
		$b4 = { 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 0F B7 90 D2 03 00 00 48 8B 84 D0 D8 03 00 00 48 83 C1 F8 }
		$b5 = { 48 8B 4E ?? E8 ?? ?? ?? 00 48 8D 7C 24 20 48 89 07 48 89 F9 E8 ?? ?? ?? ?? 48 8B 46 28 48 89 47 10 0F 10 46 18 0F 29 07 48 8B 0E E8 ?? ?? ?? 00 48 8D 7C 24 20 48 89 F9 E8 ?? ?? ?? ?? 48 8B 5E 08 48 8D 4B 18 E8 ?? ?? ?? ?? 48 C7 43 18 01 00 00 00 48 83 63 20 00 48 8B 46 08 48 89 07 48 8D 4C 24 20 E8 ?? ?? ?? ?? 90 48 83 C4 40 5B 5F 5E }
	condition:
		filesize > 500KB and filesize < 1100KB and (8 of ($a*) and 2 of ($b*)) and uint16(0) == 0x5a4d
}