s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-68345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572 high

📛 Threat Title

Unknown: AIRMed26.lnk

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: lnk. Size: 3816 bytes. Tags: lnk. Reporter: smica83. First seen: 2026-09-25 12:12:39.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 68345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572 VT 18 / 75

IOC database

Type
hash_sha256
Value
68345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 18 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan:Win/Agent.AHA
Arcabit malicious Trojan.Generic.D4DC41CA
BitDefender malicious Trojan.GenericKD.81543626
CAT-QuickHeal malicious Lnk.Trojan.A28060723
CTX malicious lnk.trojan.generic
Emsisoft malicious Trojan.GenericKD.81543626 (B)
ESET-NOD32 malicious LNK/Agent.AKL trojan
GData malicious Trojan.GenericKD.81543626
Google malicious Detected
Kaspersky malicious HEUR:Trojan.WinLNK.Agent.gen
McAfeeD malicious ti!68345507D531
MicroWorld-eScan malicious Trojan.GenericKD.81543626
Sophos malicious Troj/LnkObf-AK
Symantec malicious Trojan.Gen.NPE
Tencent malicious Win32.Trojan.Agent.Ugil
VIPRE malicious Trojan.GenericKD.81543626
VirIT malicious Trojan.LNK.Heur.A
ZoneAlarm malicious Troj/LnkObf-AK

Details From VirusTotal

Basic Properties
MD5425d6c8f15640109ccfbfa68cc61d558
SHA-12d060b0cb526c8745df9b68fe99efd100bc70e9f
SHA-25668345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572
VHash4a625b1ba7b2ac8b7044fd4ba823380c
SSDEEP96:8jBdSL9Ws3OgY9rBMJNV+MibMJ9MZM6Qv9YbM:8VM/Y9rGNV0U9MTG8
TLSHT17A718D2916D51728F3B7263958FF41819C25B94EFE32CE6D02E0C14D0865E6ADC7AF3A
File typeWindows shortcut
File type taglnk
File extensionlnk
MagicMS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=11, Archive, ctime=Wed May 11 09:07:45 2022, mtime=Fri May 17 10:03:57 2024, atime=Wed May 11 09:07:45 2022, length=862208, window=hidenormalshowminimized
File size3.7 KB
History
Creation date2022-05-11 09:07 UTC
First seen on VirusTotal2026-09-23 04:20 UTC
Last submission2026-09-23 04:20 UTC
Last analysis2026-09-25 12:24 UTC
Last modified on VirusTotal2026-09-25 14:59 UTC
Known Names
  • h7gmdvbxz.exe
  • AIRMed26.lnk
hash_sha1 2d060b0cb526c8745df9b68fe99efd100bc70e9f VT 18 / 75

IOC database

Type
hash_sha1
Value
2d060b0cb526c8745df9b68fe99efd100bc70e9f
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 18 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan:Win/Agent.AHA
Arcabit malicious Trojan.Generic.D4DC41CA
BitDefender malicious Trojan.GenericKD.81543626
CAT-QuickHeal malicious Lnk.Trojan.A28060723
CTX malicious lnk.trojan.generic
Emsisoft malicious Trojan.GenericKD.81543626 (B)
ESET-NOD32 malicious LNK/Agent.AKL trojan
GData malicious Trojan.GenericKD.81543626
Google malicious Detected
Kaspersky malicious HEUR:Trojan.WinLNK.Agent.gen
McAfeeD malicious ti!68345507D531
MicroWorld-eScan malicious Trojan.GenericKD.81543626
Sophos malicious Troj/LnkObf-AK
Symantec malicious Trojan.Gen.NPE
Tencent malicious Win32.Trojan.Agent.Ugil
VIPRE malicious Trojan.GenericKD.81543626
VirIT malicious Trojan.LNK.Heur.A
ZoneAlarm malicious Troj/LnkObf-AK

Details From VirusTotal

Basic Properties
MD5425d6c8f15640109ccfbfa68cc61d558
SHA-12d060b0cb526c8745df9b68fe99efd100bc70e9f
SHA-25668345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572
VHash4a625b1ba7b2ac8b7044fd4ba823380c
SSDEEP96:8jBdSL9Ws3OgY9rBMJNV+MibMJ9MZM6Qv9YbM:8VM/Y9rGNV0U9MTG8
TLSHT17A718D2916D51728F3B7263958FF41819C25B94EFE32CE6D02E0C14D0865E6ADC7AF3A
File typeWindows shortcut
File type taglnk
File extensionlnk
MagicMS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=11, Archive, ctime=Wed May 11 09:07:45 2022, mtime=Fri May 17 10:03:57 2024, atime=Wed May 11 09:07:45 2022, length=862208, window=hidenormalshowminimized
File size3.7 KB
History
Creation date2022-05-11 09:07 UTC
First seen on VirusTotal2026-09-23 04:20 UTC
Last submission2026-09-23 04:20 UTC
Last analysis2026-09-25 12:24 UTC
Last modified on VirusTotal2026-09-25 14:59 UTC
Known Names
  • h7gmdvbxz.exe
  • AIRMed26.lnk
hash_md5 425d6c8f15640109ccfbfa68cc61d558 VT 18 / 75

IOC database

Type
hash_md5
Value
425d6c8f15640109ccfbfa68cc61d558
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 18 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan:Win/Agent.AHA
Arcabit malicious Trojan.Generic.D4DC41CA
BitDefender malicious Trojan.GenericKD.81543626
CAT-QuickHeal malicious Lnk.Trojan.A28060723
CTX malicious lnk.trojan.generic
Emsisoft malicious Trojan.GenericKD.81543626 (B)
ESET-NOD32 malicious LNK/Agent.AKL trojan
GData malicious Trojan.GenericKD.81543626
Google malicious Detected
Kaspersky malicious HEUR:Trojan.WinLNK.Agent.gen
McAfeeD malicious ti!68345507D531
MicroWorld-eScan malicious Trojan.GenericKD.81543626
Sophos malicious Troj/LnkObf-AK
Symantec malicious Trojan.Gen.NPE
Tencent malicious Win32.Trojan.Agent.Ugil
VIPRE malicious Trojan.GenericKD.81543626
VirIT malicious Trojan.LNK.Heur.A
ZoneAlarm malicious Troj/LnkObf-AK

Details From VirusTotal

Basic Properties
MD5425d6c8f15640109ccfbfa68cc61d558
SHA-12d060b0cb526c8745df9b68fe99efd100bc70e9f
SHA-25668345507d531ab2126baad7a71b8a729f0dfc993044b2c4575f4a1c000c22572
VHash4a625b1ba7b2ac8b7044fd4ba823380c
SSDEEP96:8jBdSL9Ws3OgY9rBMJNV+MibMJ9MZM6Qv9YbM:8VM/Y9rGNV0U9MTG8
TLSHT17A718D2916D51728F3B7263958FF41819C25B94EFE32CE6D02E0C14D0865E6ADC7AF3A
File typeWindows shortcut
File type taglnk
File extensionlnk
MagicMS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=11, Archive, ctime=Wed May 11 09:07:45 2022, mtime=Fri May 17 10:03:57 2024, atime=Wed May 11 09:07:45 2022, length=862208, window=hidenormalshowminimized
File size3.7 KB
History
Creation date2022-05-11 09:07 UTC
First seen on VirusTotal2026-09-23 04:20 UTC
Last submission2026-09-23 04:20 UTC
Last analysis2026-09-25 12:24 UTC
Last modified on VirusTotal2026-09-25 14:59 UTC
Known Names
  • h7gmdvbxz.exe
  • AIRMed26.lnk

References (1)

Remediations (10)

  • web:airmed2026.com

    Airmed World Congress 2026 Munich, Germany September 16 to 18, 2026 Register here Beyond Boundaries: Cross-CompetenceEnhancement of Aeromedical Services AirMed 2026 is the leading aeromedical congress where professionals learn, debate, and connect. Join leading experts across medicine, flight operations, engineering, and public agencies for focused sessions, standout keynotes, and practical ...

  • web:assets.theregister.com

    Microsoft has quietly closed off a critical Windows shortcut file bug long abused by espionage and cybercrime networks. The flaw, tracked as CVE-2025-9491, allows malicious .lnk shortcut files to hide harmful command-line arguments from users, enabling hidden code execution when a victim opens the shortcut.

  • web:rewterz.com

    The flaw not only undermines Microsoft's mitigation strategy but also introduces a dual threat: immediate credential theft and stealthy payload staging. The vulnerability, discovered by a researcher, exploits the way Windows Explorer processes desktop shortcut (LNK) files.

  • web:thecyberthrone.in

    In August 2025, a critical vulnerability tracked as CVE-2025-9491 was publicly disclosed, impacting Microsoft Windows operating systems via a sophisticated UI misrepresentation attack vector involving .LNK shortcut files. This blog post offers a detailed technical analysis of the vulnerability, its exploitation mechanisms, and practical mitigation and detection recommendations to protect ...

  • web:windowsforum.com

    Microsoft and multiple security vendors confirm that a long-known Windows shortcut (.lnk) vulnerability tracked as CVE-2025-9491 is being actively weaponized in targeted espionage campaigns — and, as of the latest reports, there is no Microsoft patch available to close the hole.

  • web:windowsforum.com

    Microsoft's security advisory for CVE-2026-25185 names a new Windows Shell Link Processing Spoofing Vulnerability that can expose sensitive information and enable network-level spoofing—an important but medium-severity flaw that administrators should not ignore.

  • web:www.bleepingcomputer.com

    Microsoft has silently "mitigated" a high-severity Windows LNK vulnerability exploited by multiple state-backed and cybercrime hacking groups in zero-day attacks.

  • web:www.hardreset.info

    A newly confirmed remote code execution flaw in Microsoft Windows, tracked as CVE‑2025‑9491, is already exploited in the wild—and Microsoft has no patch yet. The vulnerability affects .LNK Windows shortcut files and is being used by advanced threat actors targeting diplomatic and government organisations in Europe.

  • web:www.msn.com

    Silent Patch Tuesday mitigation ends ability to hide malicious commands in .lnk files Microsoft has quietly closed off a critical Windows shortcut file bug long abused by espionage and cybercrime ...

  • web:www.trendaisecurity.com

    Trend Zero Day Initiative™ (ZDI) uncovered both state-sponsored and cybercriminal groups extensively exploiting ZDI-CAN-25373 (aka ZDI-25-148), a Windows .lnk file vulnerability that enables hidden command execution.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.