遇见数据集

Malicious and Benign Windows Shortcut (LNK) File Feature Dataset

收藏
Zenodo2026-06-23 更新2026-06-28 收录
官方服务:

资源简介:

This dataset accompanies the study "Behavior-Agnostic Structural Features for Static Detection of Malicious Windows Shortcut Files." It contains extracted static feature vectors for 1,793 Windows Shortcut (LNK) files (993 malicious, 800 benign), together with binary class labels, SHA-256/MD5 sample identifiers, and available malware-family metadata. The full 73-attribute feature representation is provided, covering structural properties (entropy, printable-character ratio, null-byte ratio, ASCII/UTF-16 string statistics, Base64-blob statistics), as well as command-related, environment-variable, URL-related, and Living-Off-the-Land Binary (LOLBIN) indicators. The progressively reduced feature subsets used in the paper's ablation study (No-LOLBIN, Aggressive Ablation, Structural-Only) can be reconstructed from this release by selecting the corresponding columns, as described in the accompanying README. Malicious samples were sourced from MalwareBazaar (operated by abuse.ch and Spamhaus). Benign samples were collected from clean Windows environments. Of the 993 malicious samples, 347 carry a non-"Unknown" malware-family label (64 distinct families) sourced from MalwareBazaar signature metadata, matching the family-labeled subset used in the paper's Leave-One-Family-Out (LOFO) generalization experiments. Raw LNK files are not included in this release.This is a deliberate choice to avoid malware redistribution. Researchers who require the raw malicious samples can re-download them from MalwareBazaar using the provided SHA-256 hashes, subject to MalwareBazaar's terms of use.

提供机构:
Zenodo
创建时间:
2026-06-23
二维码
社区交流群
二维码
科研交流群
商业服务