IOC Radar
SHA256MediumSignal 29/100

3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2d

Location
JapanJapan
First Seen
Jun 4, 2026
Last Seen
Jun 9, 2026
Jun 4
First Seen
6d ago
Jun 9
Last Seen
yesterday
2
Reports
source reports
29%
Confidence
medium
Found in 2 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
SHA-256 Hash
SHA-256 file hash — primary identifier for malware samples.
MISP Category
Artifacts Dropped
Hash Algorithm
SHA256
Confidence
29%
Signal Score
29 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

23 techniques

Feed Intelligence Summary

2 reports29% confidence
2
Source reports
29%
Confidence score
Category tags
africaasiaatlas ratbritish indian ocean territoryeuropefile-hashfirst seengermanyindiaindicatorindonesiaitalyjapanmalaysiamalwareransomwarerar archiveresearchedromulusloadersilentrunloadersingaporesouth africasyncfuture zipt1005t1027t1041t1055t1055.001t1055.003t1055.012t1056.001t1105t1113t1119t1125t1140t1204.001t1204.002t1566t1566.001t1566.002t1566.003t1571t1573.001t1574.002t1598taiwanunited kingdomvalleyratzip archive

Activity Timeline

1 total obs
Jun 9Jun 9

Threat Activity Heatmap

Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Threat ScoreLow Risk
29
SIGNAL
Signal Score
29%
Confidence
2
Reports
First seenJun 4, 2026
Last seenJun 9, 2026

VirusTotal

Not checked

WHOIS

description
The Chinese-speaking cybercriminal ecosystem has grown dramatically in recent years. Many of the threats observed in the landscape are descendants of malware first used by Chinese espionage threat actors, namely Gh0stRAT and related payloads, and frequently targeted Chinese-speaking users. But as Chinese-speaking cybercriminals develop better capabilities in malware, social engineering, and global targeting, their footprint is expanding, and more actor clusters are emerging. In this report, we’ll dive into TA4922, a newly designated Chinese-speaking threat actor largely targeting East Asia.

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 6 days ago · Last seen 1 day ago
Appeared in 2 threat reports