Esc
Double File Extension - T1036.007
(ATT&CK® Technique)
Definition
Adversaries may abuse a double extension in the filename as a means of masquerading the true file type. A file name may include a secondary file type extension that may cause only the first extension to be displayed (ex: File.txt.exe
may render in some views as just File.txt
). However, the second extension is the true file type that determines how the file is opened and executed. The real file extension may be hidden by the operating system in the file browser (ex: explorer.exe), as well as in any software configured using or similar to the system’s policies.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.