Suspicious Double Extension Files

 Original Source: [Sigma source]
Title: Suspicious Double Extension Files
Status: test
Description:Detects dropped files with double extensions, which is often used by malware as a method to abuse the fact that Windows hide default extensions by default.
References:
  -https://www.crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the-month-for-june-mustang-panda/
  -https://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations
  -https://www.cybereason.com/blog/research/a-bazar-of-tricks-following-team9s-development-cycles
  -https://twitter.com/malwrhunterteam/status/1235135745611960321
  -https://twitter.com/luc4m/status/1073181154126254080
  -https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites
  -https://vipre.com/blog/svg-phishing-attacks-the-new-trick-in-the-cybercriminals-playbook/
Author: Nasreddine Bencherchali (Nextron Systems), frack113
Date: 2022-06-19
modified:2026-03-31
Tags:
  • -'attack.stealth'
  • -'attack.t1036.007'
Logsource:
  • category: file_event
  • product: windows
Detection:
  selection_gen:
    TargetFilename|endswith:
      -'.exe'
      -'.iso'
      -'.rar'
      -'.svg'
      -'.zip'

    TargetFilename|contains:
      -'.doc.'
      -'.docx.'
      -'.gif.'
      -'.jpeg.'
      -'.jpg.'
      -'.mp3.'
      -'.mp4.'
      -'.pdf.'
      -'.png.'
      -'.ppt.'
      -'.pptx.'
      -'.rtf.'
      -'.svg.'
      -'.txt.'
      -'.xls.'
      -'.xlsx.'

  selection_exe:
    TargetFilename|endswith:
      -'.rar.exe'
      -'.zip.exe'

  filter_icons_linux:
    TargetFilename|startswith: '/usr/share/icons/'
  condition:1 of selection_* and not 1 of filter_*
Falsepositives:
  -Unlikely
Level: high