s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6 high

📛 Threat Title

Unknown: f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: lnk. Size: 108961 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:14.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6

IOC database

Type
hash_sha256
Value
f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 4e71a97f5527e760579cc06d8b9a15e16dc8c3bb VT 37 / 74

IOC database

Type
hash_sha1
Value
4e71a97f5527e760579cc06d8b9a15e16dc8c3bb
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 37 of 74 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan:Win/Agent.AE#
ALYac malicious Trojan.Agent.LNK.Gen
Antiy-AVL malicious Trojan/LNK.Powecod
Arcabit malicious Trojan.Kimsuky.64
Avast malicious Other:Malware-gen [Trj]
AVG malicious Other:Malware-gen [Trj]
Avira malicious TR/Malware
BitDefender malicious Trojan.Kimsuky.64
Bkav malicious LNK.ScriptQH.Trojan
CAT-QuickHeal malicious LNK.Exploit.Gen
CTX malicious lnk.trojan.generic
Cynet malicious Malicious (score: 99)
Emsisoft malicious Trojan.Kimsuky.64 (B)
ESET-NOD32 malicious LNK/Agent.ALD trojan
F-Secure malicious Trojan.TR/Malware
Fortinet malicious LNK/Agent.ALD!tr
GData malicious Trojan.Kimsuky.64
Google malicious Detected
huorong malicious HEUR:Trojan/LNK.Agent.b
Kaspersky malicious HEUR:Trojan.WinLNK.Powecod.e
Lionic malicious Trojan.WinLNK.Agent.4!c
McAfeeD malicious Trojan:Shortcut/GenericY.IZ
Microsoft malicious Trojan:Win32/Ravartar!rfn
MicroWorld-eScan malicious Trojan.Kimsuky.64
Rising malicious Trojan.Agent/LNK!1.1405E (CLASSIC)
Skyhigh malicious BehavesLike.Trojan.cb
Sophos malicious Troj/LnkObf-L
Symantec malicious CL.Downloader!gen211
Tencent malicious Win32.Trojan.Agent.Ocnw
TrellixENS malicious LNK/Agent.rfh
TrendMicro malicious HEUR_LNKEXEC.A
TrendMicro-HouseCall malicious HEUR_LNKEXEC.A
Varist malicious LNK/Agent.TX.gen!Eldorado
VBA32 malicious suspected of Trojan.Link.PsLauncher
VIPRE malicious Trojan.Kimsuky.64
ZoneAlarm malicious Troj/LnkObf-L
Zoner malicious Probably Heur.LNKScript

Details From VirusTotal

Basic Properties
MD5a17c290e50336f74767e543b431d0a94
SHA-14e71a97f5527e760579cc06d8b9a15e16dc8c3bb
SHA-256f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6
VHashabb77727da3c25a210d83837296d80d3
SSDEEP3072:PEZLQHb914sxerPunKJ/MC5Ii5PuulQsQcQNF:MlQneTunKJ/MOIiFuulQsQcQNF
TLSHT118B37C697CAF6C6F8A34FA7101DAB137E35A0BD62DA448A076C6A3175711D1234E3F0E
File typeWindows shortcut
File type taglnk
File extensionlnk
MagicMS Windows shortcut, Item id list present, Has Description string, Has command line arguments, Icon number=70, ctime=Mon Dec 1 10:01:11 2025, mtime=Mon Dec 1 10:01:11 2025, atime=Mon Dec 1 10:01:11 2025, length=0, window=hidenormalshowminimized
File size106.4 KB
History
Creation date2025-12-01 10:01 UTC
First seen on VirusTotal2026-06-12 14:21 UTC
Last submission2026-06-18 01:55 UTC
Last analysis2026-07-05 16:59 UTC
Last modified on VirusTotal2026-07-05 19:01 UTC
Known Names
  • link_Instagram_PXL_20240929_210802065.jpg.lnk
  • f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6.lnk
  • _f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6.lnk
hash_md5 a17c290e50336f74767e543b431d0a94 VT 37 / 74

IOC database

Type
hash_md5
Value
a17c290e50336f74767e543b431d0a94
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 37 of 74 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan:Win/Agent.AE#
ALYac malicious Trojan.Agent.LNK.Gen
Antiy-AVL malicious Trojan/LNK.Powecod
Arcabit malicious Trojan.Kimsuky.64
Avast malicious Other:Malware-gen [Trj]
AVG malicious Other:Malware-gen [Trj]
Avira malicious TR/Malware
BitDefender malicious Trojan.Kimsuky.64
Bkav malicious LNK.ScriptQH.Trojan
CAT-QuickHeal malicious LNK.Exploit.Gen
CTX malicious lnk.trojan.generic
Cynet malicious Malicious (score: 99)
Emsisoft malicious Trojan.Kimsuky.64 (B)
ESET-NOD32 malicious LNK/Agent.ALD trojan
F-Secure malicious Trojan.TR/Malware
Fortinet malicious LNK/Agent.ALD!tr
GData malicious Trojan.Kimsuky.64
Google malicious Detected
huorong malicious HEUR:Trojan/LNK.Agent.b
Kaspersky malicious HEUR:Trojan.WinLNK.Powecod.e
Lionic malicious Trojan.WinLNK.Agent.4!c
McAfeeD malicious Trojan:Shortcut/GenericY.IZ
Microsoft malicious Trojan:Win32/Ravartar!rfn
MicroWorld-eScan malicious Trojan.Kimsuky.64
Rising malicious Trojan.Agent/LNK!1.1405E (CLASSIC)
Skyhigh malicious BehavesLike.Trojan.cb
Sophos malicious Troj/LnkObf-L
Symantec malicious CL.Downloader!gen211
Tencent malicious Win32.Trojan.Agent.Ocnw
TrellixENS malicious LNK/Agent.rfh
TrendMicro malicious HEUR_LNKEXEC.A
TrendMicro-HouseCall malicious HEUR_LNKEXEC.A
Varist malicious LNK/Agent.TX.gen!Eldorado
VBA32 malicious suspected of Trojan.Link.PsLauncher
VIPRE malicious Trojan.Kimsuky.64
ZoneAlarm malicious Troj/LnkObf-L
Zoner malicious Probably Heur.LNKScript

Details From VirusTotal

Basic Properties
MD5a17c290e50336f74767e543b431d0a94
SHA-14e71a97f5527e760579cc06d8b9a15e16dc8c3bb
SHA-256f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6
VHashabb77727da3c25a210d83837296d80d3
SSDEEP3072:PEZLQHb914sxerPunKJ/MC5Ii5PuulQsQcQNF:MlQneTunKJ/MOIiFuulQsQcQNF
TLSHT118B37C697CAF6C6F8A34FA7101DAB137E35A0BD62DA448A076C6A3175711D1234E3F0E
File typeWindows shortcut
File type taglnk
File extensionlnk
MagicMS Windows shortcut, Item id list present, Has Description string, Has command line arguments, Icon number=70, ctime=Mon Dec 1 10:01:11 2025, mtime=Mon Dec 1 10:01:11 2025, atime=Mon Dec 1 10:01:11 2025, length=0, window=hidenormalshowminimized
File size106.4 KB
History
Creation date2025-12-01 10:01 UTC
First seen on VirusTotal2026-06-12 14:21 UTC
Last submission2026-06-18 01:55 UTC
Last analysis2026-07-05 16:59 UTC
Last modified on VirusTotal2026-07-05 19:01 UTC
Known Names
  • link_Instagram_PXL_20240929_210802065.jpg.lnk
  • f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6.lnk
  • _f681e7092d06f5c1399c554a4f4d52b6fcc723d1e0e7380a27906da75e4fc7e6.lnk

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: lnk. Size: 108961 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:14.

Remediations (10)

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.