Suspicious MSExchangeMailboxReplication ASPX Write

 Original Source: [Sigma source]
Title: Suspicious MSExchangeMailboxReplication ASPX Write
Status: test
Description:Detects suspicious activity in which the MSExchangeMailboxReplication process writes .asp and .apsx files to disk, which could be a sign of ProxyShell exploitation
References:
  -https://redcanary.com/blog/blackbyte-ransomware/
Author: Florian Roth (Nextron Systems)
Date: 2022-02-25
modified:None
Tags:
  • -'attack.initial-access'
  • -'attack.t1190'
  • -'attack.persistence'
  • -'attack.t1505.003'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith: '\MSExchangeMailboxReplication.exe'
    TargetFilename|endswith:
      -'.aspx'
      -'.asp'

  condition:selection
Falsepositives:
  -Unknown
Level: high