Image Masquerading as Business Document

This rule detects the creation or modification of executable files (.com, .exe, .scr, .pif, .bat, .cmd) in common user directories (Documents, Downloads, Desktop) where the initiating process is a legitimate application like explorer.exe, winrar.exe, or 7z.exe. This pattern is often used in phishing attacks where malicious executables are disguised as benign documents.