Skip to main content
← Back to Demos
Extension Mismatch beginner · 15 min

Double-Extension Masquerade: invoice.pdf.sh Bypasses the Human Eye (Emotet / QakBot Malspam Tactic)

Double-extension filenames such as invoice.pdf.sh (or the classic Windows .pdf.exe / .xls.exe) exploit the operating system's habit of hiding the true extension, so a user sees an innocent "invoice.pdf" while the shell actually executes the trailing .sh / .exe. This is a core enabler of email-borne malspam: financially motivated gangs like Emotet (TA542) and the now-disrupted QakBot leveraged double-extension lures — frequently Follina/CVE-2022-30190-adjacent document decoys and .pdf.exe droppers — to slip past users and filters that inspect only the visible name. The 2026-08-19 CISO Daily Digest's CISA KEV edition underscores that malspam and attachment-borne delivery remain a top active-exploitation vector, with actors chaining commodity loaders to ransomware. This demo recreates the masquerade safely: the malicious sample is a benign Bash script named invoice.pdf.sh that, if launched, opens the calculator as its only visible impact — no real payload, no network, no destruction. MetaDefender FileType Engine parses the true file content, exposes the mismatch between the displayed .pdf name and the actual shell script, and blocks or quarantines the file before it reaches the user. The clean counterpart shows the same document after Deep CDR has stripped the executable extension.

Attack Technique

Double extension masquerade (T1036.003)

MITRE ATT&CK

T1036.003 ↗

Platforms

linux

File Types

.cmd.sh

MetaDefender Capabilities

FileType Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---