Double Extension Masquerading - Executable Disguised as Document

This rule detects the use of double extensions in file names to masquerade executable files as benign document or media file types (e.g., 'document.pdf.exe'). This is a common technique used by attackers to trick users into executing malicious files by hiding their true extension.