Suspicious Network Communication With IPFS

 Original Source: [Sigma source]
Title: Suspicious Network Communication With IPFS
Status: test
Description:Detects connections to interplanetary file system (IPFS) containing a user's email address which mirrors behaviours observed in recent phishing campaigns leveraging IPFS to host credential harvesting webpages.
References:
  -https://blog.talosintelligence.com/ipfs-abuse/
  -https://github.com/Cisco-Talos/IOCs/tree/80caca039988252fbb3f27a2e89c2f2917f582e0/2022/11
  -https://isc.sans.edu/diary/IPFS%20phishing%20and%20the%20need%20for%20correctly%20set%20HTTP%20security%20headers/29638
Author: Gavin Knapp
Date: 2023-03-16
modified:None
Tags:
  • -'attack.collection'
  • -'attack.credential-access'
  • -'attack.t1056'
Logsource:
  • category: proxy
Detection:
  selection:
    cs-uri|re: '(?i)(ipfs\.io/|ipfs\.io\s).+\..+@.+\.[a-z]+'
  condition:selection
Falsepositives:
  -Legitimate use of IPFS being used in the organisation. However the cs-uri regex looking for a user email will likely negate this.
Level: low