MB-18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59
high
📛 Threat Title
Unknown: 18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59
Description
File type: lnk. Size: 54689 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:38.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59
IOC database
- Type
- hash_sha256
- Value
18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
d2c52d41199800ec4d485ac8423a92835b691ae8
VT 23 / 74
IOC database
- Type
- hash_sha1
- Value
d2c52d41199800ec4d485ac8423a92835b691ae8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 23 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Win/Agent.AE# |
| Antiy-AVL | malicious | Trojan/LNK.Powecod |
| Avira | malicious | TR/Malware |
| Bkav | malicious | LNK.ScriptQH.Trojan |
| CAT-QuickHeal | malicious | LNK.Exploit.Gen |
| Cynet | malicious | Malicious (score: 99) |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | LNK/Agent.ALD!tr |
| malicious | Detected |
|
| huorong | malicious | HEUR:Trojan/LNK.Agent.b |
| Lionic | malicious | Trojan.WinLNK.Agent.4!c |
| McAfeeD | malicious | Trojan:Shortcut/GenericY.IZ |
| Microsoft | malicious | Trojan:Win32/Ravartar!rfn |
| MicroWorld-eScan | malicious | Trojan.Kimsuky.51 |
| Rising | malicious | Trojan.Agent/LNK!1.1405E (CLASSIC) |
| Sophos | malicious | Troj/LnkObf-L |
| Symantec | malicious | CL.Downloader!gen211 |
| Tencent | malicious | Win32.Trojan.Agent.Ojgl |
| TrellixENS | malicious | LNK/Agent.rfh |
| Varist | malicious | LNK/Agent.TX.gen!Eldorado |
| VBA32 | malicious | suspected of Trojan.Link.PsLauncher |
| ZoneAlarm | malicious | Troj/LnkObf-L |
| Zoner | malicious | Probably Heur.LNKScript |
Details From VirusTotal
Basic Properties
| MD5 | 694d3a442fb04fc2cedbbf65f885cee1 |
| SHA-1 | d2c52d41199800ec4d485ac8423a92835b691ae8 |
| SHA-256 | 18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59 |
| VHash | 9beefa3c337de06b046a353815e81c89 |
| SSDEEP | 768:Cc+N3K/HTAcBgis0sNSzSzIp2+1019IhlDbz6Vhz7wJKFr8txr6:0dKUcGX0Duzrr1WRbUR7vOze |
| TLSH | T157334D3E399EC163CE74DF9AC2C19342B54049D770B89B01B5F6EF084062986FED5B6A |
| File type | Windows shortcut |
| File type tag | lnk |
| File extension | lnk |
| Magic | MS Windows shortcut, Item id list present, Has Description string, Has command line arguments, Icon number=70, ctime=Mon Dec 1 10:01:11 2025, mtime=Mon Dec 1 10:01:11 2025, atime=Mon Dec 1 10:01:11 2025, length=0, window=hidenormalshowminimized |
| File size | 53.4 KB |
History
| Creation date | 2025-12-01 10:01 UTC |
| First seen on VirusTotal | 2026-06-12 14:21 UTC |
| Last submission | 2026-06-16 10:55 UTC |
| Last analysis | 2026-07-03 06:44 UTC |
| Last modified on VirusTotal | 2026-07-06 11:55 UTC |
Known Names
link_Instagram_Snapchat-744461969.jpg.lnk18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59.lnk_18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59.lnk
hash_md5
694d3a442fb04fc2cedbbf65f885cee1
IOC database
- Type
- hash_md5
- Value
694d3a442fb04fc2cedbbf65f885cee1- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: lnk. Size: 54689 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:38.
Remediations (10)
-
web:bazaar.abuse.ch
You are currently viewing the MalwareBazaar entry for SHA256 18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59 . While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
-
web:learn.microsoft.com
When Microsoft released the remediation steps for this vulnerability, the data type of registry value "EnableCertPaddingCheck" = 1 as REG_SZ and we set this value as "REG_SZ" across all computers.
-
web:learn.microsoft.com
So recently I updated Windows 11 to its latest 22H2 Version. I noticed that in the properties section of my C Drive, also in the security tab there is a user named "Account Unknown (S-1-15-3-65536-1888954469-739942743-1668119174-2468466756-4239452838-1296943325-355587736-700089176) Now, my question is, is this user is associated with current version of windows? Because if I want to delete it ...
-
web:malwaretips.com
What Is a Browser Hijacker? A browser hijacker is unwanted software that changes your browser settings without clear permission. The goal is usually to route your searches and clicks through monetized redirect chains. Some hijackers are installed as extensions, while others install as Windows programs that enforce settings in the background. Modern browser hijackers commonly do things like ...
-
web:socradar.io
18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59 — SHA256 hash analysis: malware family, threat-actor attribution, MITRE ATT&CK mapping, and...
-
web:woshub.com
After a clean installation or reinstalling Windows, many unknown devices may appear in Device Manager. This article explains how to identify unknown devices in Windows, find the latest up-to-date drivers,…
-
web:www.bbb.org
Description Got a voicemail from someone claiming to be Olivia Markum from the Client Resolution Department at the Tax Relief and Remediation Agency. They said they were closing out open files and ...
-
web:www.roblox.com
Roblox is ushering in the next generation of entertainment. Imagine, create, and play together with millions of people across an infinite variety of immersive, user-generated 3D worlds.
-
web:www.toolsley.com
Free browser tool to identify unknown files based on their contents. Recognizes over 2000 file formats using libmagic. No installation necessary. Just drag & drop!
-
web:www.windowsdigitals.com
If you come across "Account Unknown " with a SID like S-1-15-3 or S-1-5-21 in the folder or drive properties, here's what you need to know.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.