Potential File Extension Spoofing Using Right-to-Left Override

 Original Source: [Sigma source]
Title: Potential File Extension Spoofing Using Right-to-Left Override
Status: test
Description:Detects suspicious filenames that contain a right-to-left override character and a potentially spoofed file extensions.
References:
  -https://redcanary.com/blog/right-to-left-override/
  -https://www.malwarebytes.com/blog/news/2014/01/the-rtlo-method
  -https://tria.ge/241015-l98snsyeje/behavioral2
  -https://www.unicode.org/versions/Unicode5.2.0/ch02.pdf
Author: Jonathan Peters (Nextron Systems), Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2024-11-17
modified:2026-03-20
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1036.002'
Logsource:
  • category: file_event
  • product: windows
Detection:
  selection_rtlo_unicode:
    TargetFilename|contains:
      -'\u202e'
      -'[U+202E]'
      -'‮'

  selection_extensions:
    TargetFilename|contains:
      -'3pm.'
      -'4pm.'
      -'cod.'
      -'fdp.'
      -'ftr.'
      -'gepj.'
      -'gnp.'
      -'gpj.'
      -'ism.'
      -'lmth.'
      -'nls.'
      -'piz.'
      -'slx.'
      -'tdo.'
      -'vsc.'
      -'vwm.'
      -'xcod.'
      -'xslx.'
      -'xtpp.'

  condition:all of selection_*
Falsepositives:
  -Filenames that contains scriptures such as arabic or hebrew might make use of this character
Level: high