LoFP LoFP / t1567.002

t1567.002

TitleTags
dns queries for \"ufile\" are not malicious by nature necessarily. investigate the source to determine the necessary actions to take
legitimate dns queries and usage of mega
legitimate mega installers and utilities are expected to communicate with this domain. exclude hosts that are known to be allowed to use this tool.
legitimate rclone usage
legitimate use of restic for backup purposes within the organization.
legitimate use of the api with a tool that the author wasn't aware of
rare legitimate access to anonfiles.com
unknown
valid requests with this exact user agent to that is used by legitimate scripts or sysadmin operations