Suspicious External WebDAV Downloads Leading to Execution via Proxy Logs

Alert on external WebDAV MiniRedir GET requests for executable-like file extensions that may lead to execution.

FreeUnreviewedSigmahighv1
title: Suspicious External WebDAV Downloads Leading to Execution via Proxy Logs
id: bf50a20b-e0dd-4af6-92bc-7bb4784ef633
related:
  - id: 4c55738d-72d8-490e-a2db-7969654e375f
    type: similar
  - id: 1ae64f96-72b6-48b3-ad3d-e71dff6c6398
    type: derived
status: test
description: This rule flags proxy traffic where the user agent indicates Microsoft WebDAV MiniRedir and the request method is GET to a URI that ends with common executable or script file extensions. It further requires the destination to not be local/private ranges, focusing on external WebDAV share usage that can precede or enable execution. The detection relies on proxy HTTP fields including user agent, request method, and requested URI, along with destination IP telemetry for filtering internal addresses.
references:
  - https://dear-territory-023.notion.site/WebDav-Share-Testing-e4950fa0c00149c3aa430d779b9b1d0f?pvs=4
  - https://micahbabinski.medium.com/search-ms-webdav-and-chill-99c5b23ac462
  - https://www.trendmicro.com/en_no/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html
  - https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/web/proxy_generic/proxy_webdav_external_execution.yml
author: Ahmed Farouk, Huntrule Team
date: 2024-05-10
tags:
  - attack.initial-access
  - attack.resource-development
  - attack.t1584
  - attack.t1566
logsource:
  category: proxy
detection:
  selection_webdav:
    c-useragent|startswith: Microsoft-WebDAV-MiniRedir/
    cs-method: GET
  selection_execution:
    c-uri|endswith:
      - .7z
      - .bat
      - .dat
      - .cmd
      - .exe
      - .js
      - .lnk
      - .ps1
      - .rar
      - .url
      - .vbe
      - .vbs
      - .zip
  filter_main_local_ips:
    dst_ip|cidr:
      - 127.0.0.0/8
      - 10.0.0.0/8
      - 172.16.0.0/12
      - 192.168.0.0/16
      - 169.254.0.0/16
      - ::1/128
      - fe80::/10
      - fc00::/7
  condition: all of selection_* and not 1 of filter_main_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule flags proxy traffic where the user agent indicates Microsoft WebDAV MiniRedir and the request method is GET to a URI that ends with common executable or script file extensions. It further requires the destination to not be local/private ranges, focusing on external WebDAV share usage that can precede or enable execution. The detection relies on proxy HTTP fields including user agent, request method, and requested URI, along with destination IP telemetry for filtering internal addresses.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.