File Concatenation of header.doc+body.doc into Windowsupdate.exe
Detects the use of the Windows command shell 'copy' utility to concatenate separate files, such as 'header.doc' and 'body.doc', into an executable file named 'Windowsupdate.exe'. This technique is commonly used by adversaries to reassemble malicious payloads that were split to evade signature-based detection or bypass security controls.
Sigma

