Suspicious File Drop by Exchange

 Original Source: [Sigma source]
Title: Suspicious File Drop by Exchange
Status: test
Description:Detects suspicious file type dropped by an Exchange component in IIS
References:
  -https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/
  -https://www.gteltsc.vn/blog/canh-bao-chien-dich-tan-cong-su-dung-lo-hong-zero-day-tren-microsoft-exchange-server-12714.html
  -https://en.gteltsc.vn/blog/cap-nhat-nhe-ve-lo-hong-bao-mat-0day-microsoft-exchange-dang-duoc-su-dung-de-tan-cong-cac-to-chuc-tai-viet-nam-9685.html
Author: Florian Roth (Nextron Systems)
Date: 2022-10-04
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.t1190'
  • -'attack.initial-access'
  • -'attack.t1505.003'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith: '\w3wp.exe'
    CommandLine|contains: 'MSExchange'
  selection_types:
    TargetFilename|endswith:
      -'.aspx'
      -'.asp'
      -'.ashx'
      -'.ps1'
      -'.bat'
      -'.exe'
      -'.dll'
      -'.vbs'

  condition:all of selection*
Falsepositives:
  -Unknown
Level: medium