{"id":"T1036.007","name":"Double File Extension","url":"https://attack.mitre.org/techniques/T1036/007","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0366","stix_id":"x-mitre-detection-strategy--92ce4302-72cb-4b7b-9184-1fc14900d0e1","name":"Detection Strategy for Double File Extension Masquerading","url":"https://attack.mitre.org/detectionstrategies/DET0366","analytics":[{"id":"AN1033","stix_id":"x-mitre-analytic--6eab694d-ea06-4487-99c4-0e21279530e8","name":"Analytic 1033","description":"Detects adversary behavior where a file with a benign-looking first extension (e.g., .txt, .jpg) ends with a dangerous second extension (e.g., .exe, .scr), and is subsequently executed. The behavior chain includes file creation with misleading naming and user or system-initiated process execution from the disguised file.","url":"https://attack.mitre.org/detectionstrategies/DET0366#AN1033","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"benign_extensions","description":"List of extensions typically used to masquerade malicious files (.txt, .jpg, .doc, .pdf)"},{"field":"dangerous_extensions","description":"List of true executable extensions that may be abused (.exe, .scr, .hta, .lnk)"},{"field":"monitored_paths","description":"Specific directories to focus on (e.g., Downloads folder, %TEMP%, Desktop)"},{"field":"TimeWindow","description":"Duration between file creation and process execution to correlate activity"},{"field":"UserContext","description":"Whether the behavior occurs in a standard user session or elevated context"}],"live":true,"detection_strategies":["DET0366"],"techniques":["T1036.007"]}],"live":true,"version":"1.0","techniques":["T1036.007"]}],"sigma_rules":[{"id":"3215aa19-f060-4332-86d5-5602511f3ca8","title":"Suspicious LNK Double Extension File Created","author":"Nasreddine Bencherchali (Nextron Systems), frack113","status":"test","level":"medium","date":"2022-11-07","modified":"2023-10-18","description":"Detects the creation of files with an \"LNK\" as a second extension. This is sometimes used by malware as a method to abuse the fact that Windows hides the \"LNK\" extension by default.\n","references":["https://www.crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the-month-for-june-mustang-panda/","https://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations","https://www.cybereason.com/blog/research/a-bazar-of-tricks-following-team9s-development-cycles","https://twitter.com/malwrhunterteam/status/1235135745611960321","https://twitter.com/luc4m/status/1073181154126254080"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.stealth","attack.t1036.007"],"path":"rules/windows/file/file_event/file_event_win_susp_lnk_double_extension.yml","techniques":["T1036.007"],"cves":[]},{"id":"5e6a80c8-2d45-4633-9ef4-fa2671a39c5c","title":"Suspicious Parent Double Extension File Execution","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-06","modified":"2023-02-28","description":"Detect execution of suspicious double extension files in ParentCommandLine","references":["https://www.virustotal.com/gui/file/7872d8845a332dce517adae9c3389fde5313ff2fed38c2577f3b498da786db68/behavior","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/bluebottle-banks-targeted-africa"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036.007"],"path":"rules/windows/process_creation/proc_creation_win_susp_double_extension_parent.yml","techniques":["T1036.007"],"cves":[]},{"id":"b4926b47-a9d7-434c-b3a0-adc3fa0bd13e","title":"Suspicious Double Extension Files","author":"Nasreddine Bencherchali (Nextron Systems), frack113","status":"test","level":"high","date":"2022-06-19","modified":"2026-03-31","description":"Detects dropped files with double extensions, which is often used by malware as a method to abuse the fact that Windows hide default extensions by default.","references":["https://www.crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the-month-for-june-mustang-panda/","https://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations","https://www.cybereason.com/blog/research/a-bazar-of-tricks-following-team9s-development-cycles","https://twitter.com/malwrhunterteam/status/1235135745611960321","https://twitter.com/luc4m/status/1073181154126254080","https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites","https://vipre.com/blog/svg-phishing-attacks-the-new-trick-in-the-cybercriminals-playbook/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.stealth","attack.t1036.007"],"path":"rules/windows/file/file_event/file_event_win_susp_double_extension.yml","techniques":["T1036.007"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}