MB-f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6
high
📛 Threat Title
Unknown: f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6
Description
File type: lnk. Size: 108961 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:14.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6
IOC database
- Type
- hash_sha256
- Value
f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
4e71a97f5527e760579cc06d8b9a15e16dc8c3bb
VT 37 / 74
IOC database
- Type
- hash_sha1
- Value
4e71a97f5527e760579cc06d8b9a15e16dc8c3bb- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 37 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Win/Agent.AE# |
| ALYac | malicious | Trojan.Agent.LNK.Gen |
| Antiy-AVL | malicious | Trojan/LNK.Powecod |
| Arcabit | malicious | Trojan.Kimsuky.64 |
| Avast | malicious | Other:Malware-gen [Trj] |
| AVG | malicious | Other:Malware-gen [Trj] |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Trojan.Kimsuky.64 |
| Bkav | malicious | LNK.ScriptQH.Trojan |
| CAT-QuickHeal | malicious | LNK.Exploit.Gen |
| CTX | malicious | lnk.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| Emsisoft | malicious | Trojan.Kimsuky.64 (B) |
| ESET-NOD32 | malicious | LNK/Agent.ALD trojan |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | LNK/Agent.ALD!tr |
| GData | malicious | Trojan.Kimsuky.64 |
| malicious | Detected |
|
| huorong | malicious | HEUR:Trojan/LNK.Agent.b |
| Kaspersky | malicious | HEUR:Trojan.WinLNK.Powecod.e |
| Lionic | malicious | Trojan.WinLNK.Agent.4!c |
| McAfeeD | malicious | Trojan:Shortcut/GenericY.IZ |
| Microsoft | malicious | Trojan:Win32/Ravartar!rfn |
| MicroWorld-eScan | malicious | Trojan.Kimsuky.64 |
| Rising | malicious | Trojan.Agent/LNK!1.1405E (CLASSIC) |
| Skyhigh | malicious | BehavesLike.Trojan.cb |
| Sophos | malicious | Troj/LnkObf-L |
| Symantec | malicious | CL.Downloader!gen211 |
| Tencent | malicious | Win32.Trojan.Agent.Ocnw |
| TrellixENS | malicious | LNK/Agent.rfh |
| TrendMicro | malicious | HEUR_LNKEXEC.A |
| TrendMicro-HouseCall | malicious | HEUR_LNKEXEC.A |
| Varist | malicious | LNK/Agent.TX.gen!Eldorado |
| VBA32 | malicious | suspected of Trojan.Link.PsLauncher |
| VIPRE | malicious | Trojan.Kimsuky.64 |
| ZoneAlarm | malicious | Troj/LnkObf-L |
| Zoner | malicious | Probably Heur.LNKScript |
Details From VirusTotal
Basic Properties
| MD5 | a17c290e50336f74767e543b431d0a94 |
| SHA-1 | 4e71a97f5527e760579cc06d8b9a15e16dc8c3bb |
| SHA-256 | f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6 |
| VHash | abb77727da3c25a210d83837296d80d3 |
| SSDEEP | 3072:PEZLQHb914sxerPunKJ/MC5Ii5PuulQsQcQNF:MlQneTunKJ/MOIiFuulQsQcQNF |
| TLSH | T118B37C697CAF6C6F8A34FA7101DAB137E35A0BD62DA448A076C6A3175711D1234E3F0E |
| File type | Windows shortcut |
| File type tag | lnk |
| File extension | lnk |
| Magic | MS Windows shortcut, Item id list present, Has Description string, Has command line arguments, Icon number=70, ctime=Mon Dec 1 10:01:11 2025, mtime=Mon Dec 1 10:01:11 2025, atime=Mon Dec 1 10:01:11 2025, length=0, window=hidenormalshowminimized |
| File size | 106.4 KB |
History
| Creation date | 2025-12-01 10:01 UTC |
| First seen on VirusTotal | 2026-06-12 14:21 UTC |
| Last submission | 2026-06-18 01:55 UTC |
| Last analysis | 2026-07-05 16:59 UTC |
| Last modified on VirusTotal | 2026-07-05 19:01 UTC |
Known Names
link_Instagram_PXL_20240929_210802065.jpg.lnkf681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6.lnk_f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6.lnk
hash_md5
a17c290e50336f74767e543b431d0a94
VT 37 / 74
IOC database
- Type
- hash_md5
- Value
a17c290e50336f74767e543b431d0a94- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 37 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Win/Agent.AE# |
| ALYac | malicious | Trojan.Agent.LNK.Gen |
| Antiy-AVL | malicious | Trojan/LNK.Powecod |
| Arcabit | malicious | Trojan.Kimsuky.64 |
| Avast | malicious | Other:Malware-gen [Trj] |
| AVG | malicious | Other:Malware-gen [Trj] |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Trojan.Kimsuky.64 |
| Bkav | malicious | LNK.ScriptQH.Trojan |
| CAT-QuickHeal | malicious | LNK.Exploit.Gen |
| CTX | malicious | lnk.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| Emsisoft | malicious | Trojan.Kimsuky.64 (B) |
| ESET-NOD32 | malicious | LNK/Agent.ALD trojan |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | LNK/Agent.ALD!tr |
| GData | malicious | Trojan.Kimsuky.64 |
| malicious | Detected |
|
| huorong | malicious | HEUR:Trojan/LNK.Agent.b |
| Kaspersky | malicious | HEUR:Trojan.WinLNK.Powecod.e |
| Lionic | malicious | Trojan.WinLNK.Agent.4!c |
| McAfeeD | malicious | Trojan:Shortcut/GenericY.IZ |
| Microsoft | malicious | Trojan:Win32/Ravartar!rfn |
| MicroWorld-eScan | malicious | Trojan.Kimsuky.64 |
| Rising | malicious | Trojan.Agent/LNK!1.1405E (CLASSIC) |
| Skyhigh | malicious | BehavesLike.Trojan.cb |
| Sophos | malicious | Troj/LnkObf-L |
| Symantec | malicious | CL.Downloader!gen211 |
| Tencent | malicious | Win32.Trojan.Agent.Ocnw |
| TrellixENS | malicious | LNK/Agent.rfh |
| TrendMicro | malicious | HEUR_LNKEXEC.A |
| TrendMicro-HouseCall | malicious | HEUR_LNKEXEC.A |
| Varist | malicious | LNK/Agent.TX.gen!Eldorado |
| VBA32 | malicious | suspected of Trojan.Link.PsLauncher |
| VIPRE | malicious | Trojan.Kimsuky.64 |
| ZoneAlarm | malicious | Troj/LnkObf-L |
| Zoner | malicious | Probably Heur.LNKScript |
Details From VirusTotal
Basic Properties
| MD5 | a17c290e50336f74767e543b431d0a94 |
| SHA-1 | 4e71a97f5527e760579cc06d8b9a15e16dc8c3bb |
| SHA-256 | f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6 |
| VHash | abb77727da3c25a210d83837296d80d3 |
| SSDEEP | 3072:PEZLQHb914sxerPunKJ/MC5Ii5PuulQsQcQNF:MlQneTunKJ/MOIiFuulQsQcQNF |
| TLSH | T118B37C697CAF6C6F8A34FA7101DAB137E35A0BD62DA448A076C6A3175711D1234E3F0E |
| File type | Windows shortcut |
| File type tag | lnk |
| File extension | lnk |
| Magic | MS Windows shortcut, Item id list present, Has Description string, Has command line arguments, Icon number=70, ctime=Mon Dec 1 10:01:11 2025, mtime=Mon Dec 1 10:01:11 2025, atime=Mon Dec 1 10:01:11 2025, length=0, window=hidenormalshowminimized |
| File size | 106.4 KB |
History
| Creation date | 2025-12-01 10:01 UTC |
| First seen on VirusTotal | 2026-06-12 14:21 UTC |
| Last submission | 2026-06-18 01:55 UTC |
| Last analysis | 2026-07-05 16:59 UTC |
| Last modified on VirusTotal | 2026-07-05 19:01 UTC |
Known Names
link_Instagram_PXL_20240929_210802065.jpg.lnkf681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6.lnk_f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6.lnk
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: lnk. Size: 108961 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:14.
Remediations (10)
-
web:blog.mindcore.dk
Step‑by‑step guide to automating the Windows Secure Boot certificate update using Microsoft Intune remediations , including fallback logic, telemetry requirements, and real‑world results.
-
web:fintel.io
These processes include detection and response, as well as vulnerability management and remediation . The Company also has a vendor risk management process to assess risks related to technology third-party service providers where we initially assess their cybersecurity posture upon engaging their services.
-
web:learn.microsoft.com
Windows for business | Windows Server | Devices and deployment | Configure application groups
-
web:learn.microsoft.com
Use the app installation error codes to help you troubleshoot app installation issues with Intune.
-
web:woshub.com
After a clean installation or reinstalling Windows, many unknown devices may appear in Device Manager. This article explains how to identify unknown devices in Windows, find the latest up-to-date drivers,…
-
web:woshub.com
The Encryption Oracle Remediation policy provides 3 levels of mitigation for the CredSSP vulnerability: Force Updated Clients - the most secure mode, which blocks vulnerable computer connections. If this option is enabled on the RDP host, it will block RDP connections from client computers with a vulnerable version of CredSSP.
-
web:www.manageengine.com
Steps to follow when software deployment fails due to unknown error code.
-
web:www.toolsley.com
Free browser tool to identify unknown files based on their contents. Recognizes over 2000 file formats using libmagic. No installation necessary. Just drag & drop!
-
web:www.windowsdigitals.com
Can't install or run an app from unknown publisher? Here's how to allow unknown publisher in Windows 11/10, and how to disable the warning.
-
web:www.windowsdigitals.com
If you come across "Account Unknown " with a SID like S-1-15-3 or S-1-5-21 in the folder or drive properties, here's what you need to know.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.