Rules Contributing to DNS Query to Anonymous File Upload Domains

The following rules are used to identify DNS queries to anonymous file upload platform domains often used for malicious purposes. Any one or more of these will trigger the DNS Query to Anonymous File Upload Domains Alert. Details for each rule can be viewed by clicking the More Details link in the description.
Title |
Description |
||||||||
---|---|---|---|---|---|---|---|---|---|
DNS Query to Anonymous File Upload Domains |
DNS query to anonymous file upload platform domains often used for malicious purposes. More details
![]() Rule IDQuery{'selection_domain': {'DnsQuestionName|endswith': ['.anonfiles.com', '.api.put.io', '.upload.put.io', '.ufile.io']}, 'condition': 'selection_domain'} Log SourceStellar Cyber Network Events configured. Rule SourceDeveloped internally by Stellar Cyber Tactics, Techniques, and ProceduresReferencesSeverity20 Suppression Logic Based On
Additional Information
|