MMC Executing Files with Reversed Extensions Using RTLO Abuse

 Original Source: [Sigma source]
Title: MMC Executing Files with Reversed Extensions Using RTLO Abuse
Status: experimental
Description:Detects malicious behavior where the MMC utility (`mmc.exe`) executes files with reversed extensions caused by Right-to-Left Override (RLO) abuse, disguising them as document formats.
References:
  -https://www.unicode.org/versions/Unicode5.2.0/ch02.pdf
  -https://en.wikipedia.org/wiki/Right-to-left_override
  -https://tria.ge/241015-l98snsyeje/behavioral2
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-02-05
modified:None
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1204.002'
  • -'attack.t1218.014'
  • -'attack.t1036.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_image:
Image|endswith:'\mmc.exe' OriginalFileName:'MMC.exe'   selection_commandline:
    CommandLine|contains:
      -'cod.msc'
      -'fdp.msc'
      -'ftr.msc'
      -'lmth.msc'
      -'slx.msc'
      -'tdo.msc'
      -'xcod.msc'
      -'xslx.msc'
      -'xtpp.msc'

  condition:all of selection_*
Falsepositives:
  -Legitimate administrative actions using MMC to execute misnamed `.msc` files.
  -Unconventional but non-malicious usage of RLO or reversed extensions.
Level: high