Executable from Webdav

 Original Source: [Sigma source]
Title: Executable from Webdav
Status: test
Description:Detects executable access via webdav6. Can be seen in APT 29 such as from the emulated APT 29 hackathon https://github.com/OTRF/detection-hackathon-apt29/
References:
  -http://carnal0wnage.attackresearch.com/2012/06/webdav-server-to-download-custom.html
  -https://github.com/OTRF/detection-hackathon-apt29
Author: SOC Prime, Adam Swan
Date: 2020-05-01
modified:2021-11-27
Tags:
  • -'attack.command-and-control'
  • -'attack.t1105'
Logsource:
  • product: zeek
  • service: http
Detection:
  selection_webdav:
c-useragent|contains:'WebDAV' c-uri|contains:'webdav'   selection_executable:
resp_mime_types|contains:'dosexec' c-uri|endswith:'.exe'   condition:selection_webdav and selection_executable
Falsepositives:
  -Unknown
Level: medium