MB-68345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572
high
📛 Threat Title
Unknown: AIRMed26.lnk
Description
File type: lnk. Size: 3816 bytes. Tags: lnk. Reporter: smica83. First seen: 2026-09-25 12:12:39.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
68345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572
VT 18 / 75
IOC database
- Type
- hash_sha256
- Value
68345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 18 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Win/Agent.AHA |
| Arcabit | malicious | Trojan.Generic.D4DC41CA |
| BitDefender | malicious | Trojan.GenericKD.81543626 |
| CAT-QuickHeal | malicious | Lnk.Trojan.A28060723 |
| CTX | malicious | lnk.trojan.generic |
| Emsisoft | malicious | Trojan.GenericKD.81543626 (B) |
| ESET-NOD32 | malicious | LNK/Agent.AKL trojan |
| GData | malicious | Trojan.GenericKD.81543626 |
| malicious | Detected |
|
| Kaspersky | malicious | HEUR:Trojan.WinLNK.Agent.gen |
| McAfeeD | malicious | ti!68345507D531 |
| MicroWorld-eScan | malicious | Trojan.GenericKD.81543626 |
| Sophos | malicious | Troj/LnkObf-AK |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Win32.Trojan.Agent.Ugil |
| VIPRE | malicious | Trojan.GenericKD.81543626 |
| VirIT | malicious | Trojan.LNK.Heur.A |
| ZoneAlarm | malicious | Troj/LnkObf-AK |
Details From VirusTotal
Basic Properties
| MD5 | 425d6c8f15640109ccfbfa68cc61d558 |
| SHA-1 | 2d060b0cb526c8745df9b68fe99efd100bc70e9f |
| SHA-256 | 68345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572 |
| VHash | 4a625b1ba7b2ac8b7044fd4ba823380c |
| SSDEEP | 96:8jBdSL9Ws3OgY9rBMJNV+MibMJ9MZM6Qv9YbM:8VM/Y9rGNV0U9MTG8 |
| TLSH | T17A718D2916D51728F3B7263958FF41819C25B94EFE32CE6D02E0C14D0865E6ADC7AF3A |
| File type | Windows shortcut |
| File type tag | lnk |
| File extension | lnk |
| Magic | MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=11, Archive, ctime=Wed May 11 09:07:45 2022, mtime=Fri May 17 10:03:57 2024, atime=Wed May 11 09:07:45 2022, length=862208, window=hidenormalshowminimized |
| File size | 3.7 KB |
History
| Creation date | 2022-05-11 09:07 UTC |
| First seen on VirusTotal | 2026-09-23 04:20 UTC |
| Last submission | 2026-09-23 04:20 UTC |
| Last analysis | 2026-09-25 12:24 UTC |
| Last modified on VirusTotal | 2026-09-25 14:59 UTC |
Known Names
h7gmdvbxz.exeAIRMed26.lnk
hash_sha1
2d060b0cb526c8745df9b68fe99efd100bc70e9f
VT 18 / 75
IOC database
- Type
- hash_sha1
- Value
2d060b0cb526c8745df9b68fe99efd100bc70e9f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 18 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Win/Agent.AHA |
| Arcabit | malicious | Trojan.Generic.D4DC41CA |
| BitDefender | malicious | Trojan.GenericKD.81543626 |
| CAT-QuickHeal | malicious | Lnk.Trojan.A28060723 |
| CTX | malicious | lnk.trojan.generic |
| Emsisoft | malicious | Trojan.GenericKD.81543626 (B) |
| ESET-NOD32 | malicious | LNK/Agent.AKL trojan |
| GData | malicious | Trojan.GenericKD.81543626 |
| malicious | Detected |
|
| Kaspersky | malicious | HEUR:Trojan.WinLNK.Agent.gen |
| McAfeeD | malicious | ti!68345507D531 |
| MicroWorld-eScan | malicious | Trojan.GenericKD.81543626 |
| Sophos | malicious | Troj/LnkObf-AK |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Win32.Trojan.Agent.Ugil |
| VIPRE | malicious | Trojan.GenericKD.81543626 |
| VirIT | malicious | Trojan.LNK.Heur.A |
| ZoneAlarm | malicious | Troj/LnkObf-AK |
Details From VirusTotal
Basic Properties
| MD5 | 425d6c8f15640109ccfbfa68cc61d558 |
| SHA-1 | 2d060b0cb526c8745df9b68fe99efd100bc70e9f |
| SHA-256 | 68345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572 |
| VHash | 4a625b1ba7b2ac8b7044fd4ba823380c |
| SSDEEP | 96:8jBdSL9Ws3OgY9rBMJNV+MibMJ9MZM6Qv9YbM:8VM/Y9rGNV0U9MTG8 |
| TLSH | T17A718D2916D51728F3B7263958FF41819C25B94EFE32CE6D02E0C14D0865E6ADC7AF3A |
| File type | Windows shortcut |
| File type tag | lnk |
| File extension | lnk |
| Magic | MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=11, Archive, ctime=Wed May 11 09:07:45 2022, mtime=Fri May 17 10:03:57 2024, atime=Wed May 11 09:07:45 2022, length=862208, window=hidenormalshowminimized |
| File size | 3.7 KB |
History
| Creation date | 2022-05-11 09:07 UTC |
| First seen on VirusTotal | 2026-09-23 04:20 UTC |
| Last submission | 2026-09-23 04:20 UTC |
| Last analysis | 2026-09-25 12:24 UTC |
| Last modified on VirusTotal | 2026-09-25 14:59 UTC |
Known Names
h7gmdvbxz.exeAIRMed26.lnk
hash_md5
425d6c8f15640109ccfbfa68cc61d558
VT 18 / 75
IOC database
- Type
- hash_md5
- Value
425d6c8f15640109ccfbfa68cc61d558- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 18 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Win/Agent.AHA |
| Arcabit | malicious | Trojan.Generic.D4DC41CA |
| BitDefender | malicious | Trojan.GenericKD.81543626 |
| CAT-QuickHeal | malicious | Lnk.Trojan.A28060723 |
| CTX | malicious | lnk.trojan.generic |
| Emsisoft | malicious | Trojan.GenericKD.81543626 (B) |
| ESET-NOD32 | malicious | LNK/Agent.AKL trojan |
| GData | malicious | Trojan.GenericKD.81543626 |
| malicious | Detected |
|
| Kaspersky | malicious | HEUR:Trojan.WinLNK.Agent.gen |
| McAfeeD | malicious | ti!68345507D531 |
| MicroWorld-eScan | malicious | Trojan.GenericKD.81543626 |
| Sophos | malicious | Troj/LnkObf-AK |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Win32.Trojan.Agent.Ugil |
| VIPRE | malicious | Trojan.GenericKD.81543626 |
| VirIT | malicious | Trojan.LNK.Heur.A |
| ZoneAlarm | malicious | Troj/LnkObf-AK |
Details From VirusTotal
Basic Properties
| MD5 | 425d6c8f15640109ccfbfa68cc61d558 |
| SHA-1 | 2d060b0cb526c8745df9b68fe99efd100bc70e9f |
| SHA-256 | 68345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572 |
| VHash | 4a625b1ba7b2ac8b7044fd4ba823380c |
| SSDEEP | 96:8jBdSL9Ws3OgY9rBMJNV+MibMJ9MZM6Qv9YbM:8VM/Y9rGNV0U9MTG8 |
| TLSH | T17A718D2916D51728F3B7263958FF41819C25B94EFE32CE6D02E0C14D0865E6ADC7AF3A |
| File type | Windows shortcut |
| File type tag | lnk |
| File extension | lnk |
| Magic | MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=11, Archive, ctime=Wed May 11 09:07:45 2022, mtime=Fri May 17 10:03:57 2024, atime=Wed May 11 09:07:45 2022, length=862208, window=hidenormalshowminimized |
| File size | 3.7 KB |
History
| Creation date | 2022-05-11 09:07 UTC |
| First seen on VirusTotal | 2026-09-23 04:20 UTC |
| Last submission | 2026-09-23 04:20 UTC |
| Last analysis | 2026-09-25 12:24 UTC |
| Last modified on VirusTotal | 2026-09-25 14:59 UTC |
Known Names
h7gmdvbxz.exeAIRMed26.lnk
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: lnk. Size: 3816 bytes. Tags: lnk. Reporter: smica83. First seen: 2026-09-25 12:12:39.
Remediations (10)
-
web:airmed2026.com
Airmed World Congress 2026 Munich, Germany September 16 to 18, 2026 Register here Beyond Boundaries: Cross-CompetenceEnhancement of Aeromedical Services AirMed 2026 is the leading aeromedical congress where professionals learn, debate, and connect. Join leading experts across medicine, flight operations, engineering, and public agencies for focused sessions, standout keynotes, and practical ...
-
web:assets.theregister.com
Microsoft has quietly closed off a critical Windows shortcut file bug long abused by espionage and cybercrime networks. The flaw, tracked as CVE-2025-9491, allows malicious .lnk shortcut files to hide harmful command-line arguments from users, enabling hidden code execution when a victim opens the shortcut.
-
web:rewterz.com
The flaw not only undermines Microsoft's mitigation strategy but also introduces a dual threat: immediate credential theft and stealthy payload staging. The vulnerability, discovered by a researcher, exploits the way Windows Explorer processes desktop shortcut (LNK) files.
-
web:thecyberthrone.in
In August 2025, a critical vulnerability tracked as CVE-2025-9491 was publicly disclosed, impacting Microsoft Windows operating systems via a sophisticated UI misrepresentation attack vector involving .LNK shortcut files. This blog post offers a detailed technical analysis of the vulnerability, its exploitation mechanisms, and practical mitigation and detection recommendations to protect ...
-
web:windowsforum.com
Microsoft and multiple security vendors confirm that a long-known Windows shortcut (.lnk) vulnerability tracked as CVE-2025-9491 is being actively weaponized in targeted espionage campaigns — and, as of the latest reports, there is no Microsoft patch available to close the hole.
-
web:windowsforum.com
Microsoft's security advisory for CVE-2026-25185 names a new Windows Shell Link Processing Spoofing Vulnerability that can expose sensitive information and enable network-level spoofing—an important but medium-severity flaw that administrators should not ignore.
-
web:www.bleepingcomputer.com
Microsoft has silently "mitigated" a high-severity Windows LNK vulnerability exploited by multiple state-backed and cybercrime hacking groups in zero-day attacks.
-
web:www.hardreset.info
A newly confirmed remote code execution flaw in Microsoft Windows, tracked as CVE‑2025‑9491, is already exploited in the wild—and Microsoft has no patch yet. The vulnerability affects .LNK Windows shortcut files and is being used by advanced threat actors targeting diplomatic and government organisations in Europe.
-
web:www.msn.com
Silent Patch Tuesday mitigation ends ability to hide malicious commands in .lnk files Microsoft has quietly closed off a critical Windows shortcut file bug long abused by espionage and cybercrime ...
-
web:www.trendaisecurity.com
Trend Zero Day Initiative™ (ZDI) uncovered both state-sponsored and cybercriminal groups extensively exploiting ZDI-CAN-25373 (aka ZDI-25-148), a Windows .lnk file vulnerability that enables hidden command execution.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.