Skip to main content
← Back to Demos
Extension Mismatch beginner · 15 min

Double Extension Masquerade Hides Executable

Double-extension files such as invoice.pdf.exe exploit the common habit of hiding known file extensions in Windows Explorer, so the visible name reads as a PDF while the file actually executes as a program. The technique is a staple of email-borne attacks, where a filename like invoice.pdf.exe slips past users and basic email filters that check only the visible extension. This demo recreates the masquerade with a benign executable, demonstrating how easy it is to deceive the human eye. MetaDefender FileType Engine parses the real file content, exposes the mismatch between the visible .pdf name and the actual PE executable, and blocks or quarantines the file before it reaches the user.

Attack Technique

Double extension masquerade

MITRE ATT&CK

T1036.003 ↗

Platforms

linuxmacoswindows

File Types

.sh

MetaDefender Capabilities

FileType Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---