This technical report examines the recent RA World ransomware attack attributed to a China-based threat actor previously involved in cyber espionage. The report identifies five indicators of compromise (IoCs), including three domains and two IP addresses, and expands on these findings by uncovering additional connected artifacts. Specifically, it details the discovery of 11 email-connected domains, two additional IP addresses, four IP-connected domains, 12 string-connected domains, and 194 string-connected subdomains. The analysis includes a review of the historical WHOIS records for the identified domains, revealing their registration details and geographical locations. Furthermore, it highlights the potential for these domains to be misused in future malicious campaigns, particularly those mimicking legitimate companies. The report concludes with a cautionary note regarding the interpretation of identified threats, emphasizing the need for further investigation to validate the findings.