What does this .lnk really run? Check it before you open it
Drop a Windows shortcut to see the program it actually launches, its full command-line arguments with any hidden whitespace padding made visible, the working directory and icon, the volume and tracker details, and the warning signs a disguised shortcut leaves behind. It works on a Mac, Linux or a phone, where the Windows-only tools cannot help.
The file is read by this tab only. It is not uploaded, nothing it names is fetched, and nothing is run.
What you get
- The target, in one line: the resolved path the shortcut points at, built from the target id list's shell items and the LinkInfo block (a local drive path, or a network share plus the common path suffix), with the working directory, the full command-line arguments in a monospace box, and the icon location.
- Padding made visible: runs of two or more spaces between arguments are drawn as dots. Windows' own Properties dialog shows only the first part of a long command line, which is exactly where a padded argument hides the part that matters.
- Header: the link flags in words, the target's file attributes, its created / modified / accessed times and size, the show command (normal, minimised or maximised) and any hotkey.
- Volume and network: the drive type, serial number and label from the VolumeID; the UNC share and any mapped drive letter from a network LinkInfo.
- Extra-data blocks: EnvironmentVariable, Tracker (the machine's NetBIOS name, the droid volume and file ids, and the MAC address recovered from the tracker's version-1 UUID), KnownFolder, SpecialFolder, Console and PropertyStore, shown where they are readable.
- Red flags, each explained: a target that is a script host or LOLBin;
-EncodedCommandarguments (the base64 decoded as UTF-16LE and shown); a URL orhiddenwindow in the arguments; arguments padded past what Properties shows; a document icon (PDF, Word, Excel, image) on an executable; a target on a network or WebDAV share; a shortcut that starts minimised. - Everything as JSON for a report or an incident ticket, saved on your own device.
Why a shortcut is worth a second look
A .lnk is not a document and not a program — it is a small binary record that tells Windows what to launch and how. That makes it a favourite delivery trick: a file called Invoice.pdf can be a shortcut wearing a PDF icon whose real target is powershell.exe with a long, padded, base64-encoded command. Double-click it and the command runs; the icon and the short name never hinted at it. Shortcuts arrive this way inside ZIPs, ISO and IMG disc images (which Windows mounts on a double-click) and e-mail attachments.
The format is Microsoft's [MS-SHLLINK] Shell Link Binary File Format: a 76-byte header (whose first four bytes are the size 4C 00 00 00 and whose class id is 00021401-0000-0000-C000-000000000046), an optional list of shell items that names the target, a LinkInfo block with the volume and path, the name / relative path / working directory / arguments / icon strings, and a chain of extra-data blocks. viewhack reads each of these with its own code, written from that specification.
The tracker block and the MAC address
Most shortcuts carry a TrackerDataBlock the Distributed Link Tracking service writes so Windows can find a moved target. It stores the NetBIOS name of the machine that created the shortcut and two "droid" identifiers. The droid file identifier is a version-1 UUID: its last six bytes are the MAC address of a network card on that machine, and its timestamp is when it was minted. viewhack reads the machine name straight out, and recovers the MAC and the time from the UUID — the same trick used to attribute the Stuxnet shortcuts. When the MAC is marked locally-administered (common on virtual machines), the page says so rather than presenting it as a real card.
How to read the same data elsewhere
On Windows, right-click the shortcut → Properties shows the target and the start of the arguments (not the padded remainder). Eric Zimmerman's LECmd and Harlan Carvey's tooling parse the whole structure on Windows; lnkinfo from liblnk does it on Linux. viewhack does it in any browser, on a phone, without installing anything and without the file leaving the tab.
What this cannot do
- It does not run anything. It reads the shortcut's bytes only; nothing it points at is launched, resolved on disk or fetched, and no URL in its arguments is contacted.
- It cannot tell you the target file is malicious. It shows what the shortcut would run and the tricks a disguise usually leaves, but it does not fetch, scan or judge the program at the end of that path.
- A clean result is not a malware scan. “No red flags” means nothing here matched the known disguises, not that the shortcut is safe. A shortcut to a legitimate program can still be unwanted, and a novel trick can leave no flag.
- The MAC and machine name describe the maker's computer, not yours, and only when a tracker block is present; a shortcut built without link tracking has none. A locally-administered MAC (many VMs) is not a hardware address.
- Some blocks are shown only partly. A PropertyStore is read for its readable string properties; a Shim or Darwin block is noted but not expanded.