Suspicious External WebDAV Downloads Leading to Execution via Proxy Logs
Alert on external WebDAV MiniRedir GET requests for executable-like file extensions that may lead to execution.
FreeUnreviewedSigmahighv1
suspicious-external-webdav-downloads-leading-to-execution-via-proxy-logs-1ae64f96
title: Suspicious External WebDAV Downloads Leading to Execution via Proxy Logs
id: bf50a20b-e0dd-4af6-92bc-7bb4784ef633
related:
- id: 4c55738d-72d8-490e-a2db-7969654e375f
type: similar
- id: 1ae64f96-72b6-48b3-ad3d-e71dff6c6398
type: derived
status: test
description: This rule flags proxy traffic where the user agent indicates Microsoft WebDAV MiniRedir and the request method is GET to a URI that ends with common executable or script file extensions. It further requires the destination to not be local/private ranges, focusing on external WebDAV share usage that can precede or enable execution. The detection relies on proxy HTTP fields including user agent, request method, and requested URI, along with destination IP telemetry for filtering internal addresses.
references:
- https://dear-territory-023.notion.site/WebDav-Share-Testing-e4950fa0c00149c3aa430d779b9b1d0f?pvs=4
- https://micahbabinski.medium.com/search-ms-webdav-and-chill-99c5b23ac462
- https://www.trendmicro.com/en_no/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html
- https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/web/proxy_generic/proxy_webdav_external_execution.yml
author: Ahmed Farouk, Huntrule Team
date: 2024-05-10
tags:
- attack.initial-access
- attack.resource-development
- attack.t1584
- attack.t1566
logsource:
category: proxy
detection:
selection_webdav:
c-useragent|startswith: Microsoft-WebDAV-MiniRedir/
cs-method: GET
selection_execution:
c-uri|endswith:
- .7z
- .bat
- .dat
- .cmd
- .exe
- .js
- .lnk
- .ps1
- .rar
- .url
- .vbe
- .vbs
- .zip
filter_main_local_ips:
dst_ip|cidr:
- 127.0.0.0/8
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
- 169.254.0.0/16
- ::1/128
- fe80::/10
- fc00::/7
condition: all of selection_* and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags proxy traffic where the user agent indicates Microsoft WebDAV MiniRedir and the request method is GET to a URI that ends with common executable or script file extensions. It further requires the destination to not be local/private ranges, focusing on external WebDAV share usage that can precede or enable execution. The detection relies on proxy HTTP fields including user agent, request method, and requested URI, along with destination IP telemetry for filtering internal addresses.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.