A named ransomware claim, a target domain, and a posted hash create a credible lead, but not proof of compromise.