DNS Query for Anonfiles.com Domain - Sysmon

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects DNS queries for "anonfiles.com", which is an anonymous file upload platform often used for malicious purposes

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "sa_dns_query" AND QUERY contains ".anonfiles.com" select Action1.HOSTNAME,Action1.MESSAGE,Action1.PROCESSNAME,Action1.QUERY,Action1.STATUSCODE,Action1.RESULT

Detection

Execution Mode

realtime

Log Sources

Windows

Author

pH-T (Nextron Systems)