Analytics BIOC Low

Office process accessed an unusual .LNK file

An attacker may embed a .LNK file in an Office document to execute malicious code.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Execution (TA0002) Persistence (TA0003)
ATT&CK techniques: User Execution (T1204) Boot or Logon Autostart Execution: Shortcut Modification (T1547.009)
Attacker's goals:

Modify or create a shortcut to gain code or program execution.

Investigative actions:

Check if the Office document contains a shortcut object. Check the content (strings) of the document object for a .LNK shortcut. Check the content of the shortcut.

Test period:
N/A (single event)
Deduplication:
7 Days