LoFP LoFP / rare legitimate access to anonfiles.com

Techniques

Sample rules

DNS Query for Anonfiles.com Domain - DNS Client

Description

Detects DNS queries for anonfiles.com, which is an anonymous file upload platform often used for malicious purposes

Detection logic

condition: selection
selection:
  EventID: 3008
  QueryName|contains: .anonfiles.com

DNS Query for Anonfiles.com Domain - Sysmon

Description

Detects DNS queries for “anonfiles.com”, which is an anonymous file upload platform often used for malicious purposes

Detection logic

condition: selection
selection:
  QueryName|contains: .anonfiles.com