There have been times when an environment is laden with a massive amount of detection alerts similar to -
Similar Detection Names:
You might also see hundreds of Threat Cases generated in relation to the above detection alerts, and they might not prove to be helpful given the nature of this Malware.
This KBA should help our customers resolve this problem by using Microsoft Autoruns and Sophos Source of Infection Tool.
MITRE's ATT&CK framework calls this TTP as Shortcut Modification and documented under T0123
"Shortcuts or symbolic links are ways of referencing other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process. Adversaries could use shortcuts to execute their tools for persistence. They may create a new shortcut as a means of indirection that may use Masquerading to look like a legitimate program. Adversaries could also edit the target path or entirely replace an existing shortcut so their tools will be executed instead of the intended legitimate program."
As expected, if we check the Property of the benign looking shortcut, it seems to be particularly suspicious because:
Target: %windir%\system32\cmd.exe /c start __ & __\DriveMgr.exe & exit
This particular issue may not be devastating in nature but is particularly annoying due to the repeated detection in the form of Toast messages from Sophos. Hence the investigation needs to be done with a planned way. We'll try to keep this simple with a 3-Step-Approach. The following sections are covered:
Applies to the following Sophos products and versions
Sophos protected Endpoints and Servers
A detection like below can be seen on Sophos protected Endpoints:
Malware detected: 'Troj/LnkRun-C' at 'I:\Loccal Disk.lnk' Malware detected: 'Troj/LnkRun-C' at 'Q:\New Volume.lnk'
The detection is flagged in the drives I: and Q: which are hosted on a File Server. It's totally normal and by-design that Sophos Anti-Virus will only block the execution of a Malware present on a Shared Network Location. It will not clean the infection. These outstanding Alerts can be safely Marked as Resolved but this action should be performed at the end of the Remediation section.
For now we should not conclude that this Endpoint is infected and shift our focus of investigation to the Server which is hosting the share. In our demonstration, the file server is called P520-2016-1 which hosts a shared folder called TestShareOn2016.
As you are aware, Sophos has a small utility called Source of Infection which can be used in situations where a typical cycle repeats:
More Information: Sophos source of infection tool (SOI): How to download and use
After running the SOI tool, we let the cycle complete on our P520-2016-1 and analyze the Source of Infection.csv generated in %temp%
If the Source of Infection is run correctly i.e. a Sophos Detection/Cleanup cycle has completed, we will have a positive confirmation of an IP which is possibly infected and needs remediation actions. In our case, we have successfully identified 192.168.30.141 to be dropping .LNK and DriveMgr.exe in a Share which is called TestShareOn2016
We will utilize a tool called Microsoft Autoruns to further investigate the machine we found in the above step.
NOTE: This malware can cleverly hide under different Users. It's advised that you switch into different users' context by clicking on the User option and check for presence of any suspicious entries.
The tool can be downloaded from here: Autoruns for Windows
MITRE ATT&ACK documents this Persistence Tactic as Registry Run Keys / Startup Folder under T1060
We have seen LNK dropping malware to persist under User's RUN Keys:
As suspected, this machine does not have a copy of Sophos Anti-Virus installed on it, and hence its spreading on the network by dropping malicious Shortcut [.LNK] files. These seemingly genuine shortcut files are often executed by Users and spreading the infection even further.
At this point, the remediation actions consist of:
You can always Open a Support Case to contact Sophos Technical Support if you need any assistance.
Sign up to the Sophos Support SMS Notification Service to get the latest product release information and critical issues.
If you've spotted an error or would like to provide feedback on this article, please use the section below to rate and comment on the article. This is invaluable to us to ensure that we continually strive to give our customers the best information possible.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. For technical support post a question to the community. Or click here for new feature/product improvements. Alternatively for paid/licensed products open a support ticket.