Jump to content

Recommended Posts

Posted

Bloody exchange server its caught some malware, during an hour period every morning, it sends out 20-30 email replies from random mailboxes with 2 random links.

Not sure its Hafnium related, we are mitigated(after the fact) but who knows what was dropped in.

 

Ran all the scans, MSERT, the PS1 scripts, Defender(which apparently is updated to scan for webshells) but nothing shows up.

 

Think I'm going to have to blast it and flip flop rebuild the DAG.

 

:mad:

Posted
Are you sure it’s on the exchange server and not sending them from elsewhere?

 

This - check your message logs to see the originating IP address of the email, or if you've got one of the emails sent out it's a header in there (x-originating-ip).

Posted
Rebuild it !! , Would reset all your admin accounts too

 

Based on the information here why would you say that? There isn't the evidence to suggest that it is something on the Exchange server. It could be coming from elsewhere and just relaying via the exchange. If that is the case the issue will come back after the rebuild.

Posted
Based on the information here why would you say that? There isn't the evidence to suggest that it is something on the Exchange server. It could be coming from elsewhere and just relaying via the exchange. If that is the case the issue will come back after the rebuild.

 

Yeah my bad , didn’t read all the posts

Posted (edited)
yeah, must be exchange, as we are getting internal to internal, not just external. headers show no other servers involved

 

If not locked down properly Internal to internal can still mean they are coming from elsewhere. Depending on the setup messages could be dumped from the elsewhere and your server still doing al the routing.

 

I’m not saying you’re wrong. But it’s more likely it’s not the exchange server that is infected.

 

Is your exchange server fully patched for both Windows updates and Exchange updates?

Edited by FN-GM
Posted
we do have a mailscanner instance in front of Exchange, which is what the SMTP from external connects to, but that is literally only the smtp port open
Posted

and the fact these are emails being replied to that are internal, ie maybe a payroll email from 2019, resent to its original recipients with a new message

 

"Good afternoon! You will find all specs in the letter via the next link:

 

 

1)tradingview.whitewaterwood-gay-spa.tw/ipsaet/deseruntnemo-1478483

 

2)freesofts.zamira.ro/idquia/autvel-1478483"

 

Dear All,

 

Due to the external payroll processing company closing early for the Christmas break, it will be necessary to bring the deadline for timesheets and expenses claims forward to midday Monday 9th December 2019 to ensure payment in December.

 

Claims received after this date will be processed in the January 2020 pay run.

 

========================

 

 

It must be internal to exchange, although I am known to be wrong! If it was random mailout, but the fact it includes an actual email

Posted
took one member of the dag down this morning, and no spam so far, might have got lucky and shut down the infected one

 

If you have found the problem server the next thing to ask is how it happened?

Guest ZFarnworth
Posted
Would you ever move to the cloud office365/google?
Guest ZFarnworth
Posted

Our school has moved fully from exchange 2013 to gmail. Staff aren’t too happy about the move but some are ok with the move.

 

And it’s free for schools [emoji16]

Posted

we are pretty sure it was fallout from hafnium, we were not patched at the time. We did find some of the signs at the time, but thought we got everything. Although we can't work out if it was a random time bomb or what that has taken it this long!

 

We will probably move to exchange online in the future, but want to do it on out terms

  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...