MB-c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590
high
📛 Threat Title
Unknown: c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590
Description
File type: lnk. Size: 100352 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:00.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590
IOC database
- Type
- hash_sha256
- Value
c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590
hash_sha1
4dc28948972504e8fdb9a63e9d94ce26bdbf78dd
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/4dc28948972504e8fdb9a63e9d94ce26bdbf78dd
IOC database
- Type
- hash_sha1
- Value
4dc28948972504e8fdb9a63e9d94ce26bdbf78dd- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/4dc28948972504e8fdb9a63e9d94ce26bdbf78dd
hash_md5
decab741dc4b7e05796dd3ccc7eeaa5f
VT 35 / 74
IOC database
- Type
- hash_md5
- Value
decab741dc4b7e05796dd3ccc7eeaa5f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 35 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Win/Agent.AE# |
| ALYac | malicious | Trojan.Agent.LNK.Gen |
| Antiy-AVL | malicious | Trojan/LNK.Agent |
| Arcabit | malicious | Trojan.Kimsuky.60 |
| Avast | malicious | Other:Malware-gen [Trj] |
| AVG | malicious | Other:Malware-gen [Trj] |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Trojan.Kimsuky.60 |
| Bkav | malicious | LNK.ScriptQH.Trojan |
| CAT-QuickHeal | malicious | LNK.Exploit.Gen |
| CTX | malicious | lnk.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| Emsisoft | malicious | Trojan.Kimsuky.60 (B) |
| ESET-NOD32 | malicious | LNK/Agent.ALD trojan |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | LNK/Agent.ALD!tr |
| GData | malicious | Trojan.Kimsuky.60 |
| malicious | Detected |
|
| huorong | malicious | HEUR:Trojan/LNK.Agent.b |
| Kaspersky | malicious | HEUR:Trojan.WinLNK.Powecod.e |
| Lionic | malicious | Trojan.WinLNK.Agent.4!c |
| McAfeeD | malicious | Trojan:Shortcut/GenericY.IZ |
| Microsoft | malicious | Trojan:Win32/Ravartar!rfn |
| MicroWorld-eScan | malicious | Trojan.Kimsuky.60 |
| Rising | malicious | Trojan.Agent/LNK!1.1405E (CLASSIC) |
| Sophos | malicious | Troj/LnkObf-L |
| Symantec | malicious | CL.Downloader!gen211 |
| Tencent | malicious | Win32.Trojan.Agent.Zylw |
| TrendMicro | malicious | HEUR_LNKEXEC.A |
| TrendMicro-HouseCall | malicious | HEUR_LNKEXEC.A |
| Varist | malicious | LNK/Agent.TX.gen!Eldorado |
| VBA32 | malicious | suspected of Trojan.Link.PsLauncher |
| VIPRE | malicious | Trojan.Kimsuky.60 |
| ZoneAlarm | malicious | Troj/LnkObf-L |
| Zoner | malicious | Probably Heur.LNKScript |
Details From VirusTotal
Basic Properties
| MD5 | decab741dc4b7e05796dd3ccc7eeaa5f |
| SHA-1 | 4dc28948972504e8fdb9a63e9d94ce26bdbf78dd |
| SHA-256 | c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590 |
| VHash | abb77727da3c25a210d83837296d80d3 |
| SSDEEP | 1536:wvuMraKC1kFuKfTa5ZJhOgzitq+pTmuk3iAdLWSMUC9YtfZqYSdXBIa99ya:wvuf19KfT2htzoqU437dLhWAfZqYSBRl |
| TLSH | T140A36C2E7E3BE306834FBFFE06CA1143B1C06FD5716ED132A2C94F595492561B28A25E |
| File type | Windows shortcut |
| File type tag | lnk |
| File extension | lnk |
| Magic | MS Windows shortcut, Item id list present, Has Description string, Has command line arguments, Icon number=70, ctime=Mon Dec 1 10:01:11 2025, mtime=Mon Dec 1 10:01:11 2025, atime=Mon Dec 1 10:01:11 2025, length=0, window=hidenormalshowminimized |
| File size | 98.0 KB |
History
| Creation date | 2025-12-01 10:01 UTC |
| First seen on VirusTotal | 2026-06-12 14:21 UTC |
| Last submission | 2026-06-16 10:50 UTC |
| Last analysis | 2026-07-02 20:45 UTC |
| Last modified on VirusTotal | 2026-07-06 11:30 UTC |
Known Names
link_Instagram_PXL_20250120_215838139.jpg.lnkc51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590.lnk
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: lnk. Size: 100352 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:00.
Remediations (10)
-
web:bazaar.abuse.ch
You are currently viewing the MalwareBazaar entry for SHA256 c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590 . While MalwareBazaar tries to identify ...
-
web:content.govdelivery.com
You are subscribed to Vulnerability Bulletins for Cybersecurity and Infrastructure Security Agency. This information has recently been updated and is now available. The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded in the past week. In some cases, the vulnerabilities in the bulletin may not yet have assigned CVSS scores. Vulnerabilities are based ...
-
web:learn.microsoft.com
So recently I updated Windows 11 to its latest 22H2 Version. I noticed that in the properties section of my C Drive, also in the security tab there is a user named "Account Unknown (S-1-15-3-65536-1888954469-739942743-1668119174-2468466756-4239452838-1296943325-355587736-700089176) Now, my question is, is this user is associated with current version of windows? Because if I want to delete it ...
-
web:maclookup.app
Fast and easy MAC address lookup on IEEE directory and Wireshark manufacturer database. Search vendor, manufacturer or organization of a device by MAC/OUI address. Fast REST API
-
web:macverify.com
Free MAC address lookup tool to identify device manufacturers. Search our database of 50,000+ vendors instantly. Find network device information by MAC address.
-
web:miniwebtool.com
MAC Address Lookup - Instantly identify network device manufacturers and vendors by MAC address. Search by full or partial MAC address, or look up MAC prefixes by company name with our comprehensive OUI database.
-
web:radar.offseq.com
Detailed information about CVE-2026-38718: n/a. Get real-time updates, technical details, and mitigation strategies.
-
web:windowsforum.com
Microsoft's Security Update Guide is the canonical place to verify which specific Windows builds and KBs include the fix for CVE-2025-53803; the general remediation pattern for kernel information-disclosure CVEs is: vendor advisory → cumulative update or security-only KB → distribution via Windows Update/WSUS and the Microsoft Update Catalog.
-
web:www.sentinelone.com
CVE-2025-30794 is a reflected XSS vulnerability in StellarWP Event Tickets. Learn about its impact, affected versions, and mitigation methods.
-
web:www.windowsdigitals.com
If you come across "Account Unknown " with a SID like S-1-15-3 or S-1-5-21 in the folder or drive properties, here's what you need to know.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.