LoFP LoFP / dns queries for \"ufile\" are not malicious by nature necessarily. investigate the source to determine the necessary actions to take

Techniques

Sample rules

DNS Query To Ufile.io

Description

Detects DNS queries to “ufile.io”, which was seen abused by malware and threat actors as a method for data exfiltration

Detection logic

condition: selection
selection:
  QueryName|contains: ufile.io

DNS Query To Ufile.io - DNS Client

Description

Detects DNS queries to “ufile.io”, which was seen abused by malware and threat actors as a method for data exfiltration

Detection logic

condition: selection
selection:
  EventID: 3008
  QueryName|contains: ufile.io