ExtensionSpoofer is a Visual Basic .NET desktop app that demonstrates how file names and icons can be visually manipulated on Windows while the underlying executable file type remains unchanged.
It uses the Unicode Right-to-Left Override character (U+202E) to reverse displayed characters in part of the file name and can swap the executable icon to match a chosen spoofed extension.
Original file name:
test_application[RIGHT_TO_LEFT_OVERRIDE]gnp.exe
Displayed in Explorer as:
test_applicationexe.png
The file still executes as an executable format.
.exe.scr.com
Note:
.comicon replacement is not always supported by the Windows shell.
- Download the precompiled executable from the latest release.
- Place the executable next to the Win10Icons folder (or choose a custom icon folder at startup).
- Open an executable file.
- Enter a file name, choose source extension and spoof extension.
- Generate the spoofed file name.
- Icon files must be valid
.icofiles. - Renaming
.png,.jpg, or other formats to.icois not sufficient. - Each icon file should be named after the target display extension (for example
pdf.ico,txt.ico).
This project is intended for education and awareness: for example, showing students why file names and icons alone are not trustworthy security indicators.
Always use responsibly and only in authorized environments.

