logo

Deep Dive: A LNK in the Chain

ID: cd3aa58e-fe16-55db-bfe4-373805e1f863

STIX ID: report--cd3aa58e-fe16-55db-bfe4-373805e1f863

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2019-05-30

Date Updated: 2026-04-28

...
...

This report analyzes a multi-stage PowerShell malware chain delivered via a malicious LNK file: mshta is used to run obfuscated VBScript that invokes PowerShell to decode embedded data, which makes staged HTTP(S) POST/GET requests to retrieve and execute additional PowerShell payloads. The final stage fingerprints the host (including VM/sandbox checks), enumerates installed applications and antivirus, implements RC4 encryption/decryption, collects system data and external IP, and posts results to a C2 endpoint while executing received commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.