IOC Radar
SHA256HighVerifiedSignal 90/100

f7b2feef2ccfdaf4d0f9f42406032f5456de076fb4c2c6baa127eb7e671fed7c

Location
UkraineUkraine
First Seen
May 23, 2026
Last Seen
Jun 19, 2026
May 23
First Seen
39d ago
Jun 19
Last Seen
12d ago
6
Reports
source reports
90%
Confidence
high
Found in 6 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
SHA-256 Hash
SHA-256 file hash — primary identifier for malware samples.
MISP Category
Artifacts Dropped
Hash Algorithm
SHA256
Confidence
90%
Signal Score
90 / 100
IDS Rule
No
Threat Context
Tags

Feed Intelligence Summary

6 reports90% confidence
6
Source reports
90%
Confidence score
Category tags
abusealienvault_ransomwareandroidbad reputationbelarusc servercobalt strikeda6ah3defensedefense evasiondetails naeastern europeeset researcheuropeexecutable fileexfiltrationexploitation activityfigurefile-hashfirstfrostyneighborgoceqc6skgovernmental targetingidleindicatorinitial accessiot securityjavascript picassoloaderjslong-sleepsmalwaremobile threatnetwork ipobfuspdf documentphishingpicassoloaderpicassoloader cpowershellransomwarerar archiveresearchedrnuarbvf urlscarcruftscriptsourcespear-phishingstrike dropperstrongsusptelecommunicationsthreat actortipsukrainez5brjsogj789

Activity Timeline

1 total obs
Jun 19Jun 19

Threat Activity Heatmap

· Peak: 2026-06-19
Less
More
Mon
Wed
Fri
Jun
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
90
SIGNAL
Signal Score
90%
Confidence
6
Reports
First seenMay 23, 2026
Last seenJun 19, 2026
Verified IOC

VirusTotal

Not checked

WHOIS

description
SHA256 of b65551d339aece718ea1465bf3542c794c445efc
references
https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/, https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/#iocs

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 month ago · Last seen 12 days ago
Appeared in 6 threat reports