Title:DNS Query To Ufile.io Status:test Description:Detects DNS queries to "ufile.io", which was seen abused by malware and threat actors as a method for data exfiltration References: -https://thedfirreport.com/2021/12/13/diavol-ransomware/ Author: yatinwad, TheDFIRReport Date: 2022-06-23 modified:2023-09-18 Tags:
-'attack.exfiltration'
-'attack.t1567.002'
Logsource:
product: windows
category: dns_query
Detection: selection: QueryName|contains:
'ufile.io' condition:selection Falsepositives:
-DNS queries for "ufile" are not malicious by nature necessarily. Investigate the source to determine the necessary actions to take Level:low