Common Information
Type Value
Value
rule lnk_wiped {
	meta:
		author = "gvenere"
		description = "LNK with wiped metadata"
	strings:
		$lnk_magic = { 4C 00 00 00 }
		$ext1 = ".js"
		$ext2 = ".bat"
		$ext3 = ".cmd"
	condition:
		$lnk_magic at 0x0 and uint16(0x1c) == 0x0 and uint16(0x24) == 0x0 and uint16(0x2c) == 0x0 and (any of ($ext*) in (0xa0 .. 0x100))
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2023-01-19 28 Following the LNK metadata trail