+ "query": "event.dns.request contains:anycase (\"api.backblazeb2.com\", \"backblazeb2.com\", \"api.dropboxapi.com\", \"content.dropboxapi.com\", \"dropboxapi.com\", \"dropbox.com\", \"g.api.mega.co.nz\", \"upload.mega.co.nz\", \"userstorage.mega.co.nz\", \"static.mega.co.nz\", \"api.mega.co.nz\", \"mega.co.nz\", \"mega.nz\", \"mega.io\", \"api.pcloud.com\", \"pcloud.com\", \"mediafire.com\", \"4shared.com\", \"api.4shared.com\", \"fex.net\", \"api.fex.net\", \"bublup.com\", \"api.bublup.com\", \"gofile.io\", \"store1.gofile.io\", \"store2.gofile.io\", \"api.gofile.io\", \"anonfiles.com\", \"api.anonfiles.com\", \"bashupload.com\", \"temp.sh\", \"transfer.sh\", \"tempsend.com\", \"sendspace.com\", \"file.io\", \"catbox.moe\", \"files.catbox.moe\", \"dropmefiles.com\", \"easyupload.io\", \"ufile.io\", \"qaz.im\", \"privat.lab\", \"share.riseup.net\", \"transfert-my-files.com\", \"oshi.at\", \"send.exploit.in\", \"bayfiles.com\", \"filetransfer.io\", \"myftp.biz\", \"myftp.org\") or url.address contains:anycase (\"api.backblazeb2.com\", \"backblazeb2.com\", \"api.dropboxapi.com\", \"content.dropboxapi.com\", \"dropboxapi.com\", \"dropbox.com\", \"g.api.mega.co.nz\", \"upload.mega.co.nz\", \"userstorage.mega.co.nz\", \"static.mega.co.nz\", \"api.mega.co.nz\", \"mega.co.nz\", \"mega.nz\", \"mega.io\", \"api.pcloud.com\", \"pcloud.com\", \"mediafire.com\", \"4shared.com\", \"api.4shared.com\", \"fex.net\", \"api.fex.net\", \"bublup.com\", \"api.bublup.com\", \"gofile.io\", \"store1.gofile.io\", \"store2.gofile.io\", \"api.gofile.io\", \"anonfiles.com\", \"api.anonfiles.com\", \"bashupload.com\", \"temp.sh\", \"transfer.sh\", \"tempsend.com\", \"sendspace.com\", \"file.io\", \"catbox.moe\", \"files.catbox.moe\", \"dropmefiles.com\", \"easyupload.io\", \"ufile.io\", \"qaz.im\", \"privat.lab\", \"share.riseup.net\", \"transfert-my-files.com\", \"oshi.at\", \"send.exploit.in\", \"bayfiles.com\", \"filetransfer.io\", \"myftp.biz\", \"myftp.org\")\n| group _FirstSeenMs=min(event.time), _LastSeenMs=max(event.time), Count=count(), UniqueSrcCmdlines=array_agg_distinct(src.process.cmdline) by endpoint.name, src.process.user, src.process.parent.name, src.process.name, src.process.verified, event.dns.request, url.address\n| let _firstSeenNs = _FirstSeenMs * 1000000\n| let _lastSeenNs = _LastSeenMs * 1000000\n| let AllSrcCmdlines = UniqueSrcCmdlines.to_string(', ')\n| columns \"first.timestamp\" = _firstSeenNs, \"last.timestamp\" = _lastSeenNs, endpoint.name, src.process.user, src.process.parent.name, src.process.name, src.process.verified, AllSrcCmdlines, event.dns.request, url.address, Count\n| sort -Count\n| limit 100000"
0 commit comments