MalwareBazaar Database

This page shows some basic information the YARA rule Methodology_Suspicious_Shortcut_SMB_URL including corresponding malware samples.

Database Entry


YARA Rule:Methodology_Suspicious_Shortcut_SMB_URL
Author:@itsreallynick (Nick Carr), @QW5kcmV3 (Andrew Thompson)
Description:Detects remote SMB path for .URL persistence
Firstseen:2022-12-15 13:46:08 UTC
Lastseen:2025-12-05 09:26:11 UTC
Sightings:215

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter