LoFP LoFP / dns queries for \"ufile\" are not malicious by nature necessarily. investigate the source to determine the necessary actions to take

Techniques

Sample rules

DNS Query To Ufile.io - DNS Client

Description

Detects DNS queries to “ufile.io”, which was seen abused by malware and threat actors as a method for data exfiltration

Detection logic

condition: selection
selection:
  EventID: 3008
  QueryName|contains: ufile.io

DNS Query To Ufile.io

Description

Detects DNS queries to “ufile.io”, which was seen abused by malware and threat actors as a method for data exfiltration

Detection logic

condition: selection
selection:
  QueryName|contains: ufile.io