Malicious SHA-256 file hash a8460f446be5… (OffSeq Mirage)
OffSeq Mirage honeypot sensors observed this SHA-256 file hash 38 time(s) in attacker activity between 2026-06-24 and 2026-07-09. Observed technique: T1105 (Ingress Tool Transfer). Seen from attacker infrastructure in VN, SG, HK, BD, NZ, BR, MO, CN. File hashes fingerprint a specific malicious payload (a dropper, web shell, miner, or post-exploitation tool) that was staged or delivered during the attack. Match it against files in your environment and your EDR/AV and threat-intel feeds.
AI Analysis
Technical Summary
The OffSeq Mirage threat intelligence platform observed a malicious payload fingerprinted by the SHA-256 hash a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 multiple times in attacker activity. The attack technique identified is T1105 (Ingress Tool Transfer), which involves transferring malicious files into a victim environment. The payload could facilitate various malicious activities such as establishing persistence or resource abuse. No specific software or systems are identified as affected, and there is no evidence of active exploitation beyond honeypot detections. This threat is an indicator of compromise useful for detection in security monitoring tools.
Potential Impact
The presence of this malicious file hash indicates potential compromise involving the transfer of a malicious payload into target environments. The payload could enable attackers to deploy droppers, web shells, miners, or post-exploitation tools, potentially leading to system compromise, persistence, or resource abuse. However, there is no confirmed active exploitation in the wild beyond honeypot observations, and no specific affected software or systems have been identified.
Mitigation Recommendations
No official patches or vendor advisories are available for this indicator. Organizations should search for the SHA-256 hash a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 within their environments and security tools such as endpoint detection and response (EDR) and antivirus solutions to detect potential presence. If detected, initiate incident response to investigate and remediate the infection. Continuous monitoring for attacker activity involving the T1105 technique (Ingress Tool Transfer) is recommended to identify related threats.
Indicators of Compromise
- hash: a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2
Malicious SHA-256 file hash a8460f446be5… (OffSeq Mirage)
Description
OffSeq Mirage honeypot sensors observed this SHA-256 file hash 38 time(s) in attacker activity between 2026-06-24 and 2026-07-09. Observed technique: T1105 (Ingress Tool Transfer). Seen from attacker infrastructure in VN, SG, HK, BD, NZ, BR, MO, CN. File hashes fingerprint a specific malicious payload (a dropper, web shell, miner, or post-exploitation tool) that was staged or delivered during the attack. Match it against files in your environment and your EDR/AV and threat-intel feeds.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The OffSeq Mirage threat intelligence platform observed a malicious payload fingerprinted by the SHA-256 hash a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 multiple times in attacker activity. The attack technique identified is T1105 (Ingress Tool Transfer), which involves transferring malicious files into a victim environment. The payload could facilitate various malicious activities such as establishing persistence or resource abuse. No specific software or systems are identified as affected, and there is no evidence of active exploitation beyond honeypot detections. This threat is an indicator of compromise useful for detection in security monitoring tools.
Potential Impact
The presence of this malicious file hash indicates potential compromise involving the transfer of a malicious payload into target environments. The payload could enable attackers to deploy droppers, web shells, miners, or post-exploitation tools, potentially leading to system compromise, persistence, or resource abuse. However, there is no confirmed active exploitation in the wild beyond honeypot observations, and no specific affected software or systems have been identified.
Defensive Guidance
No official patches or vendor advisories are available for this indicator. Organizations should search for the SHA-256 hash a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 within their environments and security tools such as endpoint detection and response (EDR) and antivirus solutions to detect potential presence. If detected, initiate incident response to investigate and remediate the infection. Continuous monitoring for attacker activity involving the T1105 technique (Ingress Tool Transfer) is recommended to identify related threats.
Technical Details
- Severity Source
- AI-assessed (no CVSS data)
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hasha8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 | OffSeq Mirage — a malicious file, observed 2026-06-24..2026-06-24, 7× |
Threat ID: 6a3c37874853345fc1c3220f
Added to database: 06/24/2026, 20:01:11 UTC
Last enriched: 07/01/2026, 20:51:47 UTC
Last updated: 08/05/2026, 09:36:41 UTC
Views: 68
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.