Double File Extension

T1036.007

Sub-technique of T1036 Masquerading.View on attack.mitre.org

About this technique

Adversaries may abuse a double extension in the filename as a means of masquerading the true file type. A file name may include a secondary file type extension that may cause only the first extension to be displayed (ex: File.txt.exe may render in some views as just File.txt). However, the second extension is the true file type that determines how the file is opened and executed. The real file extension may be hidden by the operating system in the file browser (ex: explorer.exe), as well as in any software configured using or similar to the system’s policies.

Adversaries may abuse double extensions to attempt to conceal dangerous file types of payloads. A very common usage involves tricking a user into opening what they think is a benign file type but is actually executable code. Such files often pose as email attachments and allow an adversary to gain Initial Access into a user’s system via Spearphishing Attachment then User Execution. For example, an executable file attachment named Evil.txt.exe may display as Evil.txt to a user. The user may then view it as a benign text file and open it, inadvertently executing the hidden malware.

Common file types, such as text files (.txt, .doc, etc.) and image files (.jpg, .gif, etc.) are typically used as the first extension to appear benign. Executable extensions commonly regarded as dangerous, such as .exe, .lnk, .hta, and .scr, often appear as the second extension and true file type.

Detection rules3

Rules on DetectionCode tagged with T1036.007.

Sigma3

RuleLevelLog source
Suspicious Double Extension Fileshighwindows / file_event
Suspicious Parent Double Extension File Executionhighwindows / process_creation
Suspicious LNK Double Extension File Createdmediumwindows / file_event

Splunk0

No Splunk rules are mapped to this technique yet.

Groups2

Software3

Campaigns0

None recorded.

Procedure examples5

Groups2

Used byProcedure example
GroupKimsuky

Kimsuky has used an additional filename extension to hide the true file type. Kimsuky has also masqueraded malicious LNK files as PDF objects using the double extension .pdf.lnk.

GroupMustang Panda

Mustang Panda has used an additional filename extension to hide the true file type.

Software3

Used byProcedure example
MalwareBazar

The Bazar loader has used dual-extension executable files such as PreviewReport.DOC.exe.

MalwareDarkGate

DarkGate masquerades malicious LNK files as PDF objects using the double extension .pdf.lnk.

MalwareMilan

Milan has used an executable named `companycatalog.exe.config` to appear benign.

References2

  1. PCMag DoubleExtension Open source
    PCMag. (n.d.). Encyclopedia: double extension. Retrieved August 4, 2021.
  2. SOCPrime DoubleExtension Open source
    Eugene Tkachenko. (2020, May 1). Rule of the Week: Possible Malicious File Double Extension. Retrieved July 27, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.