Suspicious Dropbox API Usage

 Original Source: [Sigma source]
Title: Suspicious Dropbox API Usage
Status: test
Description:Detects an executable that isn't dropbox but communicates with the Dropbox API
References:
  -https://app.any.run/tasks/7e906adc-9d11-447f-8641-5f40375ecebb
  -https://www.zscaler.com/blogs/security-research/new-espionage-attack-molerats-apt-targeting-users-middle-east
Author: Florian Roth (Nextron Systems)
Date: 2022-04-20
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.exfiltration'
  • -'attack.t1105'
  • -'attack.t1567.002'
Logsource:
  • category: network_connection
  • product: windows
Detection:
  selection:
    Initiated: 'true'
    DestinationHostname|endswith:
      -'api.dropboxapi.com'
      -'content.dropboxapi.com'

  filter_main_legit_dropbox:
    Image|contains: '\Dropbox'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Legitimate use of the API with a tool that the author wasn't aware of
Level: high