Skip to main content
← Back to Demos
Extension Mismatch intermediate · 15 min

Executable Disguised Behind Forged PNG Magic Bytes

Attackers routinely disguise executables by replacing the first bytes of the file — the magic bytes — with the signature of a trusted format such as PNG, so that naive checks based only on file extension or header accept the payload. The disguised binary then passes extension-based allowlists and simple scanners, arriving on the endpoint as an apparently harmless image. This demo uses a benign executable with a forged PNG header to reproduce the scenario safely. MetaDefender FileType Engine inspects the actual file structure rather than trusting the header, detects the mismatch between declared and real format, and flags the file for further inspection before it can execute.

Attack Technique

Magic byte spoofing

MITRE ATT&CK

T1036.005 ↗

Platforms

linuxmacoswindows

File Types

.png

MetaDefender Capabilities

FileType Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---