s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59 high

📛 Threat Title

Unknown: 18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: lnk. Size: 54689 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:38.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59

IOC database

Type
hash_sha256
Value
18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 d2c52d41199800ec4d485ac8423a92835b691ae8 VT 23 / 74

IOC database

Type
hash_sha1
Value
d2c52d41199800ec4d485ac8423a92835b691ae8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 23 of 74 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan:Win/Agent.AE#
Antiy-AVL malicious Trojan/LNK.Powecod
Avira malicious TR/Malware
Bkav malicious LNK.ScriptQH.Trojan
CAT-QuickHeal malicious LNK.Exploit.Gen
Cynet malicious Malicious (score: 99)
F-Secure malicious Trojan.TR/Malware
Fortinet malicious LNK/Agent.ALD!tr
Google malicious Detected
huorong malicious HEUR:Trojan/LNK.Agent.b
Lionic malicious Trojan.WinLNK.Agent.4!c
McAfeeD malicious Trojan:Shortcut/GenericY.IZ
Microsoft malicious Trojan:Win32/Ravartar!rfn
MicroWorld-eScan malicious Trojan.Kimsuky.51
Rising malicious Trojan.Agent/LNK!1.1405E (CLASSIC)
Sophos malicious Troj/LnkObf-L
Symantec malicious CL.Downloader!gen211
Tencent malicious Win32.Trojan.Agent.Ojgl
TrellixENS malicious LNK/Agent.rfh
Varist malicious LNK/Agent.TX.gen!Eldorado
VBA32 malicious suspected of Trojan.Link.PsLauncher
ZoneAlarm malicious Troj/LnkObf-L
Zoner malicious Probably Heur.LNKScript

Details From VirusTotal

Basic Properties
MD5694d3a442fb04fc2cedbbf65f885cee1
SHA-1d2c52d41199800ec4d485ac8423a92835b691ae8
SHA-25618e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59
VHash9beefa3c337de06b046a353815e81c89
SSDEEP768:Cc+N3K/HTAcBgis0sNSzSzIp2+1019IhlDbz6Vhz7wJKFr8txr6:0dKUcGX0Duzrr1WRbUR7vOze
TLSHT157334D3E399EC163CE74DF9AC2C19342B54049D770B89B01B5F6EF084062986FED5B6A
File typeWindows shortcut
File type taglnk
File extensionlnk
MagicMS Windows shortcut, Item id list present, Has Description string, Has command line arguments, Icon number=70, ctime=Mon Dec 1 10:01:11 2025, mtime=Mon Dec 1 10:01:11 2025, atime=Mon Dec 1 10:01:11 2025, length=0, window=hidenormalshowminimized
File size53.4 KB
History
Creation date2025-12-01 10:01 UTC
First seen on VirusTotal2026-06-12 14:21 UTC
Last submission2026-06-16 10:55 UTC
Last analysis2026-07-03 06:44 UTC
Last modified on VirusTotal2026-07-06 11:55 UTC
Known Names
  • link_Instagram_Snapchat-744461969.jpg.lnk
  • 18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59.lnk
  • _18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59.lnk
hash_md5 694d3a442fb04fc2cedbbf65f885cee1

IOC database

Type
hash_md5
Value
694d3a442fb04fc2cedbbf65f885cee1
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: lnk. Size: 54689 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:38.

Remediations (10)

  • web:bazaar.abuse.ch

    You are currently viewing the MalwareBazaar entry for SHA256 18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59 . While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

  • web:learn.microsoft.com

    When Microsoft released the remediation steps for this vulnerability, the data type of registry value "EnableCertPaddingCheck" = 1 as REG_SZ and we set this value as "REG_SZ" across all computers.

  • web:learn.microsoft.com

    So recently I updated Windows 11 to its latest 22H2 Version. I noticed that in the properties section of my C Drive, also in the security tab there is a user named "Account Unknown (S-1-15-3-65536-1888954469-739942743-1668119174-2468466756-4239452838-1296943325-355587736-700089176) Now, my question is, is this user is associated with current version of windows? Because if I want to delete it ...

  • web:malwaretips.com

    What Is a Browser Hijacker? A browser hijacker is unwanted software that changes your browser settings without clear permission. The goal is usually to route your searches and clicks through monetized redirect chains. Some hijackers are installed as extensions, while others install as Windows programs that enforce settings in the background. Modern browser hijackers commonly do things like ...

  • web:socradar.io

    18e387b068d3de5ffe5386aeea07f7baccd8207c583e04797f8c4dfbed6dbf59 — SHA256 hash analysis: malware family, threat-actor attribution, MITRE ATT&CK mapping, and...

  • web:woshub.com

    After a clean installation or reinstalling Windows, many unknown devices may appear in Device Manager. This article explains how to identify unknown devices in Windows, find the latest up-to-date drivers,…

  • web:www.bbb.org

    Description Got a voicemail from someone claiming to be Olivia Markum from the Client Resolution Department at the Tax Relief and Remediation Agency. They said they were closing out open files and ...

  • web:www.roblox.com

    Roblox is ushering in the next generation of entertainment. Imagine, create, and play together with millions of people across an infinite variety of immersive, user-generated 3D worlds.

  • web:www.toolsley.com

    Free browser tool to identify unknown files based on their contents. Recognizes over 2000 file formats using libmagic. No installation necessary. Just drag & drop!

  • web:www.windowsdigitals.com

    If you come across "Account Unknown " with a SID like S-1-15-3 or S-1-5-21 in the folder or drive properties, here's what you need to know.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.