SHA256MediumSignal 29/100
66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60d
First Seen
Jun 4, 2026
Last Seen
Jun 7, 2026
Found in 2 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
SHA-256 Hash
SHA-256 file hash — primary identifier for malware samples.
MISP Category
Artifacts Dropped
Hash Algorithm
SHA256
Confidence
29%
Signal Score
29 / 100
IDS Rule
No
Threat Context
Tags
Feed Intelligence Summary
2 reports29% confidence
2
Source reports
29%
Confidence score
Category tags
atlas ratfile-hashfirst seenindicatorransomwarerar archiveresearchedromulusloadersilentrunloadersyncfuture zipzip archive
Activity Timeline
Jun 7Jun 7
Threat Activity Heatmap
· Peak: 2026-06-07LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreLow Risk
29
SIGNAL
Signal Score
29%
Confidence
2
Reports
First seenJun 4, 2026
Last seenJun 7, 2026
VirusTotal
Not checked
WHOIS
- description
- The Chinese-speaking cybercriminal ecosystem has grown dramatically in recent years. Many of the threats observed in the landscape are descendants of malware first used by Chinese espionage threat actors, namely Gh0stRAT and related payloads, and frequently targeted Chinese-speaking users. But as Chinese-speaking cybercriminals develop better capabilities in malware, social engineering, and global targeting, their footprint is expanding, and more actor clusters are emerging. In this report, we’ll dive into TA4922, a newly designated Chinese-speaking threat actor largely targeting East Asia.
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 11 days ago · Last seen 7 days ago
Appeared in 2 threat reports