Double Extension Masquerade Hides Executable
Double-extension files such as invoice.pdf.exe exploit the common habit of hiding known file extensions in Windows Explorer, so the visible name reads as a PDF while the file actually executes as a program. The technique is a staple of email-borne attacks, where a filename like invoice.pdf.exe slips past users and basic email filters that check only the visible extension. This demo recreates the masquerade with a benign executable, demonstrating how easy it is to deceive the human eye. MetaDefender FileType Engine parses the real file content, exposes the mismatch between the visible .pdf name and the actual PE executable, and blocks or quarantines the file before it reaches the user.
Attack Technique
Double extension masquerade
MITRE ATT&CK
T1036.003 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗