This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Double Extension Files
Original Source:
[Sigma source]
Title:
Suspicious Double Extension Files
Status:
test
Description:
Detects dropped files with double extensions, which is often used by malware as a method to abuse the fact that Windows hide default extensions by default.
References:
-https://www.crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the-month-for-june-mustang-panda/
-https://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations
-https://www.cybereason.com/blog/research/a-bazar-of-tricks-following-team9s-development-cycles
-https://twitter.com/malwrhunterteam/status/1235135745611960321
-https://twitter.com/luc4m/status/1073181154126254080
-https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites
-https://vipre.com/blog/svg-phishing-attacks-the-new-trick-in-the-cybercriminals-playbook/
Author:
Nasreddine Bencherchali (Nextron Systems), frack113
Date:
2022-06-19
modified:
2026-03-31
Tags:
-'attack.stealth'
-'attack.t1036.007'
Logsource:
category: file_event
product: windows
Detection:
selection_gen:
TargetFilename|endswith
:
-'.exe'
-'.iso'
-'.rar'
-'.svg'
-'.zip'
TargetFilename|contains
:
-'.doc.'
-'.docx.'
-'.gif.'
-'.jpeg.'
-'.jpg.'
-'.mp3.'
-'.mp4.'
-'.pdf.'
-'.png.'
-'.ppt.'
-'.pptx.'
-'.rtf.'
-'.svg.'
-'.txt.'
-'.xls.'
-'.xlsx.'
selection_exe:
TargetFilename|endswith
:
-'.rar.exe'
-'.zip.exe'
filter_icons_linux:
TargetFilename|startswith
:
'/usr/share/icons/'
condition
:
1 of selection_* and not 1 of filter_*
Falsepositives:
-Unlikely
Level:
high