viewhack

What does this .lnk really run? Check it before you open it

Drop a Windows shortcut to see the program it actually launches, its full command-line arguments with any hidden whitespace padding made visible, the working directory and icon, the volume and tracker details, and the warning signs a disguised shortcut leaves behind. It works on a Mac, Linux or a phone, where the Windows-only tools cannot help.

The file is read by this tab only. It is not uploaded, nothing it names is fetched, and nothing is run.

What you get

Why a shortcut is worth a second look

A .lnk is not a document and not a program — it is a small binary record that tells Windows what to launch and how. That makes it a favourite delivery trick: a file called Invoice.pdf can be a shortcut wearing a PDF icon whose real target is powershell.exe with a long, padded, base64-encoded command. Double-click it and the command runs; the icon and the short name never hinted at it. Shortcuts arrive this way inside ZIPs, ISO and IMG disc images (which Windows mounts on a double-click) and e-mail attachments.

The format is Microsoft's [MS-SHLLINK] Shell Link Binary File Format: a 76-byte header (whose first four bytes are the size 4C 00 00 00 and whose class id is 00021401-0000-0000-C000-000000000046), an optional list of shell items that names the target, a LinkInfo block with the volume and path, the name / relative path / working directory / arguments / icon strings, and a chain of extra-data blocks. viewhack reads each of these with its own code, written from that specification.

The tracker block and the MAC address

Most shortcuts carry a TrackerDataBlock the Distributed Link Tracking service writes so Windows can find a moved target. It stores the NetBIOS name of the machine that created the shortcut and two "droid" identifiers. The droid file identifier is a version-1 UUID: its last six bytes are the MAC address of a network card on that machine, and its timestamp is when it was minted. viewhack reads the machine name straight out, and recovers the MAC and the time from the UUID — the same trick used to attribute the Stuxnet shortcuts. When the MAC is marked locally-administered (common on virtual machines), the page says so rather than presenting it as a real card.

How to read the same data elsewhere

On Windows, right-click the shortcut → Properties shows the target and the start of the arguments (not the padded remainder). Eric Zimmerman's LECmd and Harlan Carvey's tooling parse the whole structure on Windows; lnkinfo from liblnk does it on Linux. viewhack does it in any browser, on a phone, without installing anything and without the file leaving the tab.

What this cannot do

  • It does not run anything. It reads the shortcut's bytes only; nothing it points at is launched, resolved on disk or fetched, and no URL in its arguments is contacted.
  • It cannot tell you the target file is malicious. It shows what the shortcut would run and the tricks a disguise usually leaves, but it does not fetch, scan or judge the program at the end of that path.
  • A clean result is not a malware scan. “No red flags” means nothing here matched the known disguises, not that the shortcut is safe. A shortcut to a legitimate program can still be unwanted, and a novel trick can leave no flag.
  • The MAC and machine name describe the maker's computer, not yours, and only when a tracker block is present; a shortcut built without link tracking has none. A locally-administered MAC (many VMs) is not a hardware address.
  • Some blocks are shown only partly. A PropertyStore is read for its readable string properties; a Shim or Darwin block is noted but not expanded.