s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590 high

📛 Threat Title

Unknown: c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: lnk. Size: 100352 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:00.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590

IOC database

Type
hash_sha256
Value
c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590

hash_sha1 4dc28948972504e8fdb9a63e9d94ce26bdbf78dd VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/4dc28948972504e8fdb9a63e9d94ce26bdbf78dd

IOC database

Type
hash_sha1
Value
4dc28948972504e8fdb9a63e9d94ce26bdbf78dd
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/4dc28948972504e8fdb9a63e9d94ce26bdbf78dd

hash_md5 decab741dc4b7e05796dd3ccc7eeaa5f VT 35 / 74

IOC database

Type
hash_md5
Value
decab741dc4b7e05796dd3ccc7eeaa5f
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 35 of 74 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan:Win/Agent.AE#
ALYac malicious Trojan.Agent.LNK.Gen
Antiy-AVL malicious Trojan/LNK.Agent
Arcabit malicious Trojan.Kimsuky.60
Avast malicious Other:Malware-gen [Trj]
AVG malicious Other:Malware-gen [Trj]
Avira malicious TR/Malware
BitDefender malicious Trojan.Kimsuky.60
Bkav malicious LNK.ScriptQH.Trojan
CAT-QuickHeal malicious LNK.Exploit.Gen
CTX malicious lnk.trojan.generic
Cynet malicious Malicious (score: 99)
Emsisoft malicious Trojan.Kimsuky.60 (B)
ESET-NOD32 malicious LNK/Agent.ALD trojan
F-Secure malicious Trojan.TR/Malware
Fortinet malicious LNK/Agent.ALD!tr
GData malicious Trojan.Kimsuky.60
Google malicious Detected
huorong malicious HEUR:Trojan/LNK.Agent.b
Kaspersky malicious HEUR:Trojan.WinLNK.Powecod.e
Lionic malicious Trojan.WinLNK.Agent.4!c
McAfeeD malicious Trojan:Shortcut/GenericY.IZ
Microsoft malicious Trojan:Win32/Ravartar!rfn
MicroWorld-eScan malicious Trojan.Kimsuky.60
Rising malicious Trojan.Agent/LNK!1.1405E (CLASSIC)
Sophos malicious Troj/LnkObf-L
Symantec malicious CL.Downloader!gen211
Tencent malicious Win32.Trojan.Agent.Zylw
TrendMicro malicious HEUR_LNKEXEC.A
TrendMicro-HouseCall malicious HEUR_LNKEXEC.A
Varist malicious LNK/Agent.TX.gen!Eldorado
VBA32 malicious suspected of Trojan.Link.PsLauncher
VIPRE malicious Trojan.Kimsuky.60
ZoneAlarm malicious Troj/LnkObf-L
Zoner malicious Probably Heur.LNKScript

Details From VirusTotal

Basic Properties
MD5decab741dc4b7e05796dd3ccc7eeaa5f
SHA-14dc28948972504e8fdb9a63e9d94ce26bdbf78dd
SHA-256c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590
VHashabb77727da3c25a210d83837296d80d3
SSDEEP1536:wvuMraKC1kFuKfTa5ZJhOgzitq+pTmuk3iAdLWSMUC9YtfZqYSdXBIa99ya:wvuf19KfT2htzoqU437dLhWAfZqYSBRl
TLSHT140A36C2E7E3BE306834FBFFE06CA1143B1C06FD5716ED132A2C94F595492561B28A25E
File typeWindows shortcut
File type taglnk
File extensionlnk
MagicMS Windows shortcut, Item id list present, Has Description string, Has command line arguments, Icon number=70, ctime=Mon Dec 1 10:01:11 2025, mtime=Mon Dec 1 10:01:11 2025, atime=Mon Dec 1 10:01:11 2025, length=0, window=hidenormalshowminimized
File size98.0 KB
History
Creation date2025-12-01 10:01 UTC
First seen on VirusTotal2026-06-12 14:21 UTC
Last submission2026-06-16 10:50 UTC
Last analysis2026-07-02 20:45 UTC
Last modified on VirusTotal2026-07-06 11:30 UTC
Known Names
  • link_Instagram_PXL_20250120_215838139.jpg.lnk
  • c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590.lnk

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: lnk. Size: 100352 bytes. Tags: Kimsuky, lnk, orange-bizarre-lynx-526-mypinata-cloud, uni-site-je--mort-php. Reporter: JAMESWT_WT. First seen: 2026-06-16 10:47:00.

Remediations (10)

  • web:bazaar.abuse.ch

    You are currently viewing the MalwareBazaar entry for SHA256 c51c984a00eb7c833585353ac010f1546026e8924f27b6d0aeabd52a7d16b590 . While MalwareBazaar tries to identify ...

  • web:content.govdelivery.com

    You are subscribed to Vulnerability Bulletins for Cybersecurity and Infrastructure Security Agency. This information has recently been updated and is now available. The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded in the past week. In some cases, the vulnerabilities in the bulletin may not yet have assigned CVSS scores. Vulnerabilities are based ...

  • web:learn.microsoft.com

    So recently I updated Windows 11 to its latest 22H2 Version. I noticed that in the properties section of my C Drive, also in the security tab there is a user named "Account Unknown (S-1-15-3-65536-1888954469-739942743-1668119174-2468466756-4239452838-1296943325-355587736-700089176) Now, my question is, is this user is associated with current version of windows? Because if I want to delete it ...

  • web:maclookup.app

    Fast and easy MAC address lookup on IEEE directory and Wireshark manufacturer database. Search vendor, manufacturer or organization of a device by MAC/OUI address. Fast REST API

  • web:macverify.com

    Free MAC address lookup tool to identify device manufacturers. Search our database of 50,000+ vendors instantly. Find network device information by MAC address.

  • web:miniwebtool.com

    MAC Address Lookup - Instantly identify network device manufacturers and vendors by MAC address. Search by full or partial MAC address, or look up MAC prefixes by company name with our comprehensive OUI database.

  • web:radar.offseq.com

    Detailed information about CVE-2026-38718: n/a. Get real-time updates, technical details, and mitigation strategies.

  • web:windowsforum.com

    Microsoft's Security Update Guide is the canonical place to verify which specific Windows builds and KBs include the fix for CVE-2025-53803; the general remediation pattern for kernel information-disclosure CVEs is: vendor advisory → cumulative update or security-only KB → distribution via Windows Update/WSUS and the Microsoft Update Catalog.

  • web:www.sentinelone.com

    CVE-2025-30794 is a reflected XSS vulnerability in StellarWP Event Tickets. Learn about its impact, affected versions, and mitigation methods.

  • web:www.windowsdigitals.com

    If you come across "Account Unknown " with a SID like S-1-15-3 or S-1-5-21 in the folder or drive properties, here's what you need to know.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.