You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
From FireEye Red Team Tool Countermeasures:
LNKSmasher embeds an arbitrary payload in an LNK that can be executed by the embedded command. This IOC will detect the commands executed by both the new and old version of LNKSmasher.
Additional Details
Detail
Value
Type
Templated Match
Category
Execution
Apply Risk to Entities
device_hostname, user_username
Signal Name
LNKSmasher Utility Commands
Summary Expression
Command with LNKSmasher Utility indicators detected on host: {{device_hostname}}