Static detection of malicious windows shortcut files without content-specific indicators
Windows Shortcut (LNK) files are widely abused for malware delivery. Static detectors often rely on content-specific indicators such as commands, URLs, paths, and trusted-binary references. This study examines whether malicious shortcuts remain detectable when these indicators are excluded from the model inputs, without modifying or executing the files. Systematic feature ablation reduces 73 static features to nine byte-distribution and string statistics. Models are evaluated using stratified hold-out testing and tests that exclude one malware family from training at a time. Hold-out ROC-AUC and mean family-level ROC-AUC were above 0.99. UTF-16 string statistics, null-byte ratio, and entropy contributed most strongly to classification. Case-level analysis shows that missed samples overlap with benign shortcuts in the retained features and that some retain additional content-specific clues. Lower precision in family-held-out tests and increasing false-positive rates at higher recall limit standalone use. These findings support structural features as a complementary static screening layer, with independent validation and threshold selection needed before deployment. The extracted-feature dataset is publicly available (DOI: 10.5281/zenodo.20811599 ).
Authors
- Muhammed Saadetdin KAYA (ORCID: https://orcid.org/0000-0003-1749-5604)
Institutions
- Ankara University (TR)
Publication Details
- Journal
- Forensic Science International Digital Investigation
- Published
- 2026-09-17
- DOI
- https://doi.org/10.1016/j.fsidi.2026.302215
- Primary Topic
- Advanced Malware Detection Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00