Static detection of malicious windows shortcut files without content-specific indicators

Windows Shortcut (LNK) files are widely abused for malware delivery. Static detectors often rely on content-specific indicators such as commands, URLs, paths, and trusted-binary references. This study examines whether malicious shortcuts remain detectable when these indicators are excluded from the model inputs, without modifying or executing the files. Systematic feature ablation reduces 73 static features to nine byte-distribution and string statistics. Models are evaluated using stratified hold-out testing and tests that exclude one malware family from training at a time. Hold-out ROC-AUC and mean family-level ROC-AUC were above 0.99. UTF-16 string statistics, null-byte ratio, and entropy contributed most strongly to classification. Case-level analysis shows that missed samples overlap with benign shortcuts in the retained features and that some retain additional content-specific clues. Lower precision in family-held-out tests and increasing false-positive rates at higher recall limit standalone use. These findings support structural features as a complementary static screening layer, with independent validation and threshold selection needed before deployment. The extracted-feature dataset is publicly available (DOI: 10.5281/zenodo.20811599 ).

Authors

Institutions

Publication Details

Journal
Forensic Science International Digital Investigation
Published
2026-09-17
DOI
https://doi.org/10.1016/j.fsidi.2026.302215
Primary Topic
Advanced Malware Detection Techniques
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Static detection of malicious windows shortcut files without content-specific indicators

Muhammed Saadetdin KAYA
Forensic Science International Digital Investigation
Advanced Malware Detection Techniques
article

Static detection of malicious windows shortcut files without content-specific indicators

Muhammed Saadetdin KAYA
article en

Abstract

Windows Shortcut (LNK) files are widely abused for malware delivery. Static detectors often rely on content-specific indicators such as commands, URLs, paths, and trusted-binary references. This study examines whether malicious shortcuts remain detectable when these indicators are excluded from the model inputs, without modifying or executing the files. Systematic feature ablation reduces 73 static features to nine byte-distribution and string statistics. Models are evaluated using stratified hold-out testing and tests that exclude one malware family from training at a time. Hold-out ROC-AUC and mean family-level ROC-AUC were above 0.99. UTF-16 string statistics, null-byte ratio, and entropy contributed most strongly to classification. Case-level analysis shows that missed samples overlap with benign shortcuts in the retained features and that some retain additional content-specific clues. Lower precision in family-held-out tests and increasing false-positive rates at higher recall limit standalone use. These findings support structural features as a complementary static screening layer, with independent validation and threshold selection needed before deployment. The extracted-feature dataset is publicly available (DOI: 10.5281/zenodo.20811599 ).

Forensic Science International Digital InvestigationVol. 59
Ankara University (TR)
Peace, Justice and strong institutions
Openalex Percentile: Top 9%
Advanced Malware Detection Techniques
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Static detection of malicious windows shortcut files without content-specific indicators — Muhammed Saadetdin KAYA · Forensic Science International Digital Investigation (2026) | TGRS Research Map | TGRS