Netskope Threat Labs

FILE-IDENTIFY Portable Executable (PE) binary possibly embedded within another PE

IPS-SWG

1 SID: 170040

First seen
July 2024
Last seen
July 2024

Detects a portable executable (PE) header embedded inside another PE binary. Nested executables typically indicate a packed or dropper payload hiding a second stage, so this signature flags likely malware in transit.