{"id":"29f171d7-aa47-42c7-9c7b-3c87938164d9","title":"DNS Query for Anonfiles.com Domain - DNS Client","description":"Detects DNS queries for anonfiles.com, which is an anonymous file upload platform often used for malicious purposes","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-16","modified":"","tags":["attack.exfiltration","attack.t1567.002"],"technique_ids":["T1567.002"],"logsource":{"product":"windows","service":"dns-client","definition":"Requirements: Microsoft-Windows-DNS Client Events/Operational Event Log must be enabled/collected in order to receive the events."},"falsepositives":["Rare legitimate access to anonfiles.com"],"references":["https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte"],"source_path":"rules/windows/builtin/dns_client/win_dns_client_anonymfiles_com.yml","source_sha256":"964d4db5ec9c1d3dd5c9c852ec3ae08aa9c6ba011f34632ff387434366e38c57","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/dns_client/win_dns_client_anonymfiles_com.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: DNS Query for Anonfiles.com Domain - DNS Client\nid: 29f171d7-aa47-42c7-9c7b-3c87938164d9\nrelated:\n    - id: 065cceea-77ec-4030-9052-fc0affea7110\n      type: similar\nstatus: test\ndescription: Detects DNS queries for anonfiles.com, which is an anonymous file upload platform often used for malicious purposes\nreferences:\n    - https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte\nauthor: Nasreddine Bencherchali (Nextron Systems)\ndate: 2023-01-16\ntags:\n    - attack.exfiltration\n    - attack.t1567.002\nlogsource:\n    product: windows\n    service: dns-client\n    definition: 'Requirements: Microsoft-Windows-DNS Client Events/Operational Event Log must be enabled/collected in order to receive the events.'\ndetection:\n    selection:\n        EventID: 3008\n        QueryName|contains: '.anonfiles.com'\n    condition: selection\nfalsepositives:\n    - Rare legitimate access to anonfiles.com\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1567.002","id":"T1567.002","name":"Exfiltration to Cloud Storage","page":"techniques/enterprise/T1567.002/"}],"data_path":"data/detection-rules/29f171d7-aa47-42c7-9c7b-3c87938164d9.json","kind":"sigma"}
