Renamed Fsquirt.exe Execution

Rule Info

Name
Renamed Fsquirt.exe Execution
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects execution of a renamed fsquirt.exe (Bluetooth File Transfer Wizard). fsquirt.exe can be abused to side-load a malicious bthprops.cpl, thus attackers may rename fsquirt.exe to evade whitelisting or detection mechanisms.
Date
2026-02-04 00:00:00
Modified
None
Id
0f67d6e0-8899-4ea4-a8c3-93b5758da45c
Tags
attack.defense-evasion attack.t1036
Type
Nextron Sigma feed only (private)

Rule History