Verdict
- VT_HIGH_DETECTION_RATIO 30% or more of VirusTotal vendors flag the indicator.
Key indicators
- SHA256
- b55fbe9358dd4b5825ce459e84cd0823ecdf7b64550fe1af968306047b7de5c9
- File name
- ntdll.dll
- File type
- Win32 EXE
- Family
- trojan.akira/megazord
- First submitted
- 2024-06-14
- First seen
- 2024-06-14 (834 days before · VirusTotal)
- Last seen
- 2026-05-24 (125 days before)
Relationship graph
Expand| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.akira/megazord. The analysis is old, but a file's content does not change. Win32 EXE file; vendors name it akira, megazord. Sandboxes: 1 of 2 sandboxes: malicious. | 58/75 | 125 days old | Strong | |
| Referenced in 17 community pulses, which are unverified. | — | — | Neutral |
Coverage · checked, no record: MalwareBazaar, ThreatFox, CIRCL hashlookup · failed: none
Analyst summary
Consistent with engineMalicious, medium confidence. 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.akira/megazord. The analysis is old, but a file's content does not change. Win32 EXE file; vendors name it akira, megazord. Sandboxes: 1 of 2 sandboxes: malicious. It rests on one source family, so confidence is medium.
Why the evidence points to malicious
- [VirusTotal] 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.akira/megazord. The analysis is old, but a file's content does not change. Win32 EXE file; vendors name it akira, megazord. Sandboxes: 1 of 2 sandboxes: malicious.
Attribution
The evidence does not establish who operates this indicator.
Threat context
Context onlyAll evidence
5 sources queried · click a row for its raw fields · ages computed by the engine| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.akira/megazord. The analysis is old, but a file's content does not change. Win32 EXE file; vendors name it akira, megazord. Sandboxes: 1 of 2 sandboxes: malicious. | 58/75 | 125 days old | Strong | |
| Referenced in 17 community pulses, which are unverified. | — | — | Neutral | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record |
Engine rules applied
- HASH_NOT_TIME_DECAYEDFile-hash evidence does not decay: an old analysis date does not make a file benign.
- VT_HIGH_DETECTION_RATIO30% or more of VirusTotal vendors flag the indicator.
- SINGLE_SOURCE_ONLYOnly one source family provides malicious evidence.
Analyst summary
Consistent with engineMalicious, medium confidence. 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.akira/megazord. The analysis is old, but a file's content does not change. Win32 EXE file; vendors name it akira, megazord. Sandboxes: 1 of 2 sandboxes: malicious. It rests on one source family, so confidence is medium.
Why the evidence points to malicious
- [VirusTotal] 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.akira/megazord. The analysis is old, but a file's content does not change. Win32 EXE file; vendors name it akira, megazord. Sandboxes: 1 of 2 sandboxes: malicious.
Attribution
The evidence does not establish who operates this indicator.
Key indicators
- SHA256
- b55fbe9358dd4b5825ce459e84cd0823ecdf7b64550fe1af968306047b7de5c9
- File name
- ntdll.dll
- File type
- Win32 EXE
- Family
- trojan.akira/megazord
- First submitted
- 2024-06-14
- First seen
- 2024-06-14 (834 days before · VirusTotal)
- Last seen
- 2026-05-24 (125 days before)
By source
No infrastructure source returned a record.
Relationship graph
Click a node for details · edges are observed relationships, not ownershipEvidence timeline
- 2026-05-24VirusTotal: 58/75 vendors (77.3%) flag it: strong multi-vendor detection
- 2026-09-26Investigated
Run history
2 collections of this indicator- 2026-09-29MALICIOUS83Stored evidenceOpen · newest
- 2026-09-26MALICIOUS82Stored evidenceShown
Sources are checked again on every live run, so a source that has since dropped the indicator from its feed can change the verdict. Each run keeps the evidence exactly as it was collected.
Recommended next steps
- huntSearch EDR for b55fbe9358dd... across all endpoints.
- blockAdd the hash to the EDR blocklist.
Pivot to other tools
Opens the indicator in the source's own site (new tab).

