{"id":"1cbbeaaf-3c8c-4e4c-9d72-49485b6a176b","title":"DNS Query To Ufile.io","description":"Detects DNS queries to \"ufile.io\", which was seen abused by malware and threat actors as a method for data exfiltration","author":"yatinwad, TheDFIRReport","status":"test","level":"low","date":"2022-06-23","modified":"2023-09-18","tags":["attack.exfiltration","attack.t1567.002"],"technique_ids":["T1567.002"],"logsource":{"product":"windows","category":"dns_query"},"falsepositives":["DNS queries for \"ufile\" are not malicious by nature necessarily. Investigate the source to determine the necessary actions to take"],"references":["https://thedfirreport.com/2021/12/13/diavol-ransomware/"],"source_path":"rules/windows/dns_query/dns_query_win_ufile_io_query.yml","source_sha256":"94024dae793a7a5c9a49b510edc37ad40e17b94538e3a993cdda3856433067f4","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/dns_query/dns_query_win_ufile_io_query.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: DNS Query To Ufile.io\nid: 1cbbeaaf-3c8c-4e4c-9d72-49485b6a176b\nrelated:\n    - id: 090ffaad-c01a-4879-850c-6d57da98452d\n      type: similar\nstatus: test\ndescription: Detects DNS queries to \"ufile.io\", which was seen abused by malware and threat actors as a method for data exfiltration\nreferences:\n    - https://thedfirreport.com/2021/12/13/diavol-ransomware/\nauthor: yatinwad, TheDFIRReport\ndate: 2022-06-23\nmodified: 2023-09-18\ntags:\n    - attack.exfiltration\n    - attack.t1567.002\nlogsource:\n    product: windows\n    category: dns_query\ndetection:\n    selection:\n        QueryName|contains: 'ufile.io'\n    condition: selection\nfalsepositives:\n    - DNS queries for \"ufile\" are not malicious by nature necessarily. Investigate the source to determine the necessary actions to take\nlevel: low\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1567.002","id":"T1567.002","name":"Exfiltration to Cloud Storage","page":"techniques/enterprise/T1567.002/"}],"data_path":"data/detection-rules/1cbbeaaf-3c8c-4e4c-9d72-49485b6a176b.json","kind":"sigma"}
