Windows File Creation: Suspicious LNK Double-Extension Targeted by Document/Image Prefixes
Alerts on Windows-created filenames that end in .lnk while containing hidden-looking double extensions (e.g., .doc. .pdf.)
- Product
- windows
- Category
- file_event
- Author
- Nasreddine Bencherchali (Nextron Systems), frack113 (SigmaHQ), DRL 1.1
- Published
- 2022-11-07
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows file creation events where the target filename ends with “.lnk” while also containing a second extension pattern such as “.doc.”, “.pdf.”, “.jpg.”, or Office extensions embedded in the name. Double-extension LNK filenames are often used to mislead users by leveraging Windows default file-extension hiding behavior. The detection relies on file event telemetry that includes the created/target filename and process image path so it can exclude common “Recent” locations and selected Office executables.
Reporting behind it
- crowdstrike.comhttps://www.crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the-month-for-june-mustang-panda/
- anomali.comhttps://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations
- cybereason.comhttps://www.cybereason.com/blog/research/a-bazar-of-tricks-following-team9s-development-cycles
- twitter.comhttps://twitter.com/malwrhunterteam/status/1235135745611960321
- twitter.comhttps://twitter.com/luc4m/status/1073181154126254080
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_lnk_double_extension.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows File Creation: Suspicious LNK Double-Extension Targeted by Document/Image Prefixes"
id: 4e0f6aa5-22b5-4a67-9920-33e5c33cd66b
related:
- id: b4926b47-a9d7-434c-b3a0-adc3fa0bd13e
type: derived
- id: 3215aa19-f060-4332-86d5-5602511f3ca8
type: derived
status: test
description: This rule flags Windows file creation events where the target filename ends with “.lnk” while also containing a second extension pattern such as “.doc.”, “.pdf.”, “.jpg.”, or Office extensions embedded in the name. Double-extension LNK filenames are often used to mislead users by leveraging Windows default file-extension hiding behavior. The detection relies on file event telemetry that includes the created/target filename and process image path so it can exclude common “Recent” locations and selected Office executables.
references:
- https://www.crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the-month-for-june-mustang-panda/
- https://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations
- https://www.cybereason.com/blog/research/a-bazar-of-tricks-following-team9s-development-cycles
- https://twitter.com/malwrhunterteam/status/1235135745611960321
- https://twitter.com/luc4m/status/1073181154126254080
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_lnk_double_extension.yml
author: Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule Team
date: 2022-11-07
modified: 2023-10-18
tags:
- attack.stealth
- attack.t1036.007
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|endswith: .lnk
TargetFilename|contains:
- .doc.
- .docx.
- .jpg.
- .pdf.
- .ppt.
- .pptx.
- .xls.
- .xlsx.
filter_main_recent:
TargetFilename|contains: \AppData\Roaming\Microsoft\Windows\Recent\
filter_optional_office_recent:
Image|endswith:
- \excel.exe
- \powerpnt.exe
- \winword.exe
TargetFilename|contains: \AppData\Roaming\Microsoft\Office\Recent\
filter_optional_office_excel:
Image|endswith: \excel.exe
TargetFilename|contains: \AppData\Roaming\Microsoft\Excel
filter_optional_office_powerpoint:
Image|endswith: \powerpnt.exe
TargetFilename|contains: \AppData\Roaming\Microsoft\PowerPoint
filter_optional_office_word:
Image|endswith: \winword.exe
TargetFilename|contains: \AppData\Roaming\Microsoft\Word
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Some tuning is required for other general purpose directories of third party apps
level: medium
regression_tests_path: regression_data/rules/windows/file/file_event/file_event_win_susp_lnk_double_extension/info.yml
license: DRL-1.1