A suspicious executable with multiple file extensions was created
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Execution (TA0002), Stealth (TA0005)
ATT&CK Technique
User Execution: Malicious File (T1204.002), Masquerading: Double File Extension (T1036.007)
Severity
Medium
Description
An executable file with multiple extensions was created. This technique is frequently used to disguise malware as user content.
Attacker's Goals
Bypassing defenses and/or tricking the user into executing a file that seems like a trustworthy file.
Investigative actions
Investigate the actor process and the file created to determine if it was used for legitimate purposes or malicious activity.
Was this helpful?
