{"id":"090ffaad-c01a-4879-850c-6d57da98452d","title":"DNS Query To Ufile.io - DNS Client","description":"Detects DNS queries to \"ufile.io\", which was seen abused by malware and threat actors as a method for data exfiltration","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2023-01-16","modified":"2023-09-18","tags":["attack.exfiltration","attack.t1567.002"],"technique_ids":["T1567.002"],"logsource":{"product":"windows","service":"dns-client","definition":"Requirements: Microsoft-Windows-DNS Client Events/Operational Event Log must be enabled/collected in order to receive the events."},"falsepositives":["DNS queries for \"ufile\" are not malicious by nature necessarily. Investigate the source to determine the necessary actions to take"],"references":["https://thedfirreport.com/2021/12/13/diavol-ransomware/"],"source_path":"rules/windows/builtin/dns_client/win_dns_client_ufile_io.yml","source_sha256":"dbe92e553aa3bde0672df9cc7a2c8d8f5154ec4fda2b3af41a58b61512c53b19","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/dns_client/win_dns_client_ufile_io.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: DNS Query To Ufile.io - DNS Client\nid: 090ffaad-c01a-4879-850c-6d57da98452d\nrelated:\n    - id: 1cbbeaaf-3c8c-4e4c-9d72-49485b6a176b\n      type: similar\nstatus: test\ndescription: Detects DNS queries to \"ufile.io\", which was seen abused by malware and threat actors as a method for data exfiltration\nreferences:\n    - https://thedfirreport.com/2021/12/13/diavol-ransomware/\nauthor: Nasreddine Bencherchali (Nextron Systems)\ndate: 2023-01-16\nmodified: 2023-09-18\ntags:\n    - attack.exfiltration\n    - attack.t1567.002\nlogsource:\n    product: windows\n    service: dns-client\n    definition: 'Requirements: Microsoft-Windows-DNS Client Events/Operational Event Log must be enabled/collected in order to receive the events.'\ndetection:\n    selection:\n        EventID: 3008\n        QueryName|contains: 'ufile.io'\n    condition: selection\nfalsepositives:\n    - DNS queries for \"ufile\" are not malicious by nature necessarily. Investigate the source to determine the necessary actions to take\nlevel: low\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1567.002","id":"T1567.002","name":"Exfiltration to Cloud Storage","page":"techniques/enterprise/T1567.002/"}],"data_path":"data/detection-rules/090ffaad-c01a-4879-850c-6d57da98452d.json","kind":"sigma"}
