Skip to content

Hide Navigation Hide TOC

Suspicious Double Extension Files (b4926b47-a9d7-434c-b3a0-adc3fa0bd13e)

Detects dropped files with double extensions, which is often used by malware as a method to abuse the fact that Windows hide default extensions by default.

Cluster A Galaxy A Cluster B Galaxy B Level
Suspicious Double Extension Files (b4926b47-a9d7-434c-b3a0-adc3fa0bd13e) Sigma-Rules Double File Extension - T1036.007 (11f29a39-0942-4d62-92b6-fe236cf3066e) Attack Pattern 1
Double File Extension - T1036.007 (11f29a39-0942-4d62-92b6-fe236cf3066e) Attack Pattern Masquerading - T1036 (42e8de7b-37b2-4258-905a-6897815e58e0) Attack Pattern 2