title: Suspicious Double Extension id: 1cdd9a09-06c9-4769-99ff-626e2b3991b8 description: Detects suspicious use of an .exe extension after a non-executable file extension like .pdf.exe, a set of spaces or underlines to cloak the executable file in spear phishing campaigns references: - https://blu3-team.blogspot.com/2019/06/misleading-extensions-xlsexe-docexe.html - https://twitter.com/blackorbird/status/1140519090961825792 author: Florian Roth (rule), @blu3_team (idea) date: 2019/06/26 tags: - attack.initial_access - attack.t1566.001 - attack.t1193 # an old one logsource: category: process_creation product: windows detection: selection: Image: - '*.doc.exe' - '*.docx.exe' - '*.xls.exe' - '*.xlsx.exe' - '*.ppt.exe' - '*.pptx.exe' - '*.rtf.exe' - '*.pdf.exe' - '*.txt.exe' - '* .exe' - '*______.exe' condition: selection falsepositives: - Unknown level: critical