Windows Explorer ZIP Extraction Dropping Startup Folder Shortcut

Alert on explorer.exe writing Startup-folder LNK files whose names include {0AFACED1-E828-11D1-9187-B532F1E9575D}, indicating shortcut-based persistence.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Greg (rule) (SigmaHQ), DRL 1.1
Published
2022-07-21
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags file activity consistent with a ZIP-based phishing flow where a user expands content via Windows Explorer and results in creation of a malicious shortcut in the Startup folder. The shortcut naming includes the specific {0AFACED1-E828-11D1-9187-B532F1E9575D} pattern associated with a folder shortcut operation. It relies on Windows file event telemetry showing a .lnk.{0AFACED1-E828-11D1-9187-B532F1E9575D} target under the Startup path created by explorer.exe.

Related detections8 linkedT1547 — drag to rearrange
Suspicious Boot Verification Program Persistence via Registry (via registry_set)
SwimSnake Driver Execution Persistence via Session Manager PlatformExecute (via registry_set)
Suspicious Session Manager Execute Value Modification for Persistence (via registry_set)
Suspicious RDP Wds StartupPrograms Persistence Modification (via registry_set)
Windows: GPO Modification Adds Startup/Logon Script References
Windows grpconv Utility Execution with Output Option
Windows: Suspicious Driver Installation via pnputil.exe
Windows Registry Run Key Modification via winekey or team9 backdoor
Windows Explorer ZIP Extraction Dropping Startup Folder Shortcut
Pivot detection · T1547 · 8 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.