Skip to content

Hide Navigation Hide TOC

Suspicious Double Extension Files (b4926b47-a9d7-434c-b3a0-adc3fa0bd13e)

Detects dropped files with double extensions, which is often used by malware as a method to abuse the fact that Windows hide default extensions by default.

Cluster A Galaxy A Cluster B Galaxy B Level
Double File Extension - T1036.007 (11f29a39-0942-4d62-92b6-fe236cf3066e) Attack Pattern Suspicious Double Extension Files (b4926b47-a9d7-434c-b3a0-adc3fa0bd13e) Sigma-Rules 1
Masquerading - T1036 (42e8de7b-37b2-4258-905a-6897815e58e0) Attack Pattern Double File Extension - T1036.007 (11f29a39-0942-4d62-92b6-fe236cf3066e) Attack Pattern 2