CAWJames Posted October 28, 2021 Posted October 28, 2021 Bloody exchange server its caught some malware, during an hour period every morning, it sends out 20-30 email replies from random mailboxes with 2 random links. Not sure its Hafnium related, we are mitigated(after the fact) but who knows what was dropped in. Ran all the scans, MSERT, the PS1 scripts, Defender(which apparently is updated to scan for webshells) but nothing shows up. Think I'm going to have to blast it and flip flop rebuild the DAG.
3s-gtech Posted October 28, 2021 Posted October 28, 2021 Yeah, rebuild. You’ll never trust it otherwise.
CAWJames Posted October 28, 2021 Author Posted October 28, 2021 yep, remove a member at a time, rebuild it, add it back in, rinse and repeat. oh the joys
FN-GM Posted October 28, 2021 Posted October 28, 2021 Are you sure it’s on the exchange server and not sending them from elsewhere?
Bedders Posted October 28, 2021 Posted October 28, 2021 Are you sure it’s on the exchange server and not sending them from elsewhere? This - check your message logs to see the originating IP address of the email, or if you've got one of the emails sent out it's a header in there (x-originating-ip).
Jcx500 Posted October 29, 2021 Posted October 29, 2021 Rebuild it !! , Would reset all your admin accounts too
FN-GM Posted October 29, 2021 Posted October 29, 2021 Rebuild it !! , Would reset all your admin accounts too Based on the information here why would you say that? There isn't the evidence to suggest that it is something on the Exchange server. It could be coming from elsewhere and just relaying via the exchange. If that is the case the issue will come back after the rebuild.
Jcx500 Posted October 29, 2021 Posted October 29, 2021 Based on the information here why would you say that? There isn't the evidence to suggest that it is something on the Exchange server. It could be coming from elsewhere and just relaying via the exchange. If that is the case the issue will come back after the rebuild. Yeah my bad , didn’t read all the posts
3s-gtech Posted October 29, 2021 Posted October 29, 2021 It’s certainly worth checking first, as the others have said and if you haven’t already. Have you disabled IMAP and POP?
CAWJames Posted October 29, 2021 Author Posted October 29, 2021 yeah, must be exchange, as we are getting internal to internal, not just external. headers show no other servers involved
FN-GM Posted October 29, 2021 Posted October 29, 2021 (edited) yeah, must be exchange, as we are getting internal to internal, not just external. headers show no other servers involved If not locked down properly Internal to internal can still mean they are coming from elsewhere. Depending on the setup messages could be dumped from the elsewhere and your server still doing al the routing. I’m not saying you’re wrong. But it’s more likely it’s not the exchange server that is infected. Is your exchange server fully patched for both Windows updates and Exchange updates? Edited October 29, 2021 by FN-GM
CAWJames Posted October 29, 2021 Author Posted October 29, 2021 Fully patched Ex2016, no IMAP or POP3 access externally, SMTP and the 443 infrastructure is, via load balancer
CAWJames Posted October 29, 2021 Author Posted October 29, 2021 we do have a mailscanner instance in front of Exchange, which is what the SMTP from external connects to, but that is literally only the smtp port open
CAWJames Posted October 29, 2021 Author Posted October 29, 2021 and the fact these are emails being replied to that are internal, ie maybe a payroll email from 2019, resent to its original recipients with a new message "Good afternoon! You will find all specs in the letter via the next link: 1)tradingview.whitewaterwood-gay-spa.tw/ipsaet/deseruntnemo-1478483 2)freesofts.zamira.ro/idquia/autvel-1478483" Dear All, Due to the external payroll processing company closing early for the Christmas break, it will be necessary to bring the deadline for timesheets and expenses claims forward to midday Monday 9th December 2019 to ensure payment in December. Claims received after this date will be processed in the January 2020 pay run. ======================== It must be internal to exchange, although I am known to be wrong! If it was random mailout, but the fact it includes an actual email
CAWJames Posted October 29, 2021 Author Posted October 29, 2021 took one member of the dag down this morning, and no spam so far, might have got lucky and shut down the infected one
FN-GM Posted October 29, 2021 Posted October 29, 2021 took one member of the dag down this morning, and no spam so far, might have got lucky and shut down the infected one If you have found the problem server the next thing to ask is how it happened?
Guest ZFarnworth Posted October 29, 2021 Posted October 29, 2021 Would you ever move to the cloud office365/google?
Guest ZFarnworth Posted October 29, 2021 Posted October 29, 2021 Our school has moved fully from exchange 2013 to gmail. Staff aren’t too happy about the move but some are ok with the move. And it’s free for schools [emoji16]
k-strider Posted October 29, 2021 Posted October 29, 2021 have a look at google workspace sysnc for outlook.... our office staff are much happier with that than using gmail web mail.
CAWJames Posted October 29, 2021 Author Posted October 29, 2021 we are pretty sure it was fallout from hafnium, we were not patched at the time. We did find some of the signs at the time, but thought we got everything. Although we can't work out if it was a random time bomb or what that has taken it this long! We will probably move to exchange online in the future, but want to do it on out terms
CAWJames Posted November 11, 2021 Author Posted November 11, 2021 Confirmed to be "SquirrelWaffle", rebuilt servers and it came back, what a nasty little bit of nastiness
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now