ProxyLogon MSExchange OabVirtualDirectory

 Original Source: [Sigma source]
Title: ProxyLogon MSExchange OabVirtualDirectory
Status: test
Description:Detects specific patterns found after a successful ProxyLogon exploitation in relation to a Commandlet invocation of Set-OabVirtualDirectory
References:
  -https://bi-zone.medium.com/hunting-down-ms-exchange-attacks-part-1-proxylogon-cve-2021-26855-26858-27065-26857-6e885c5f197c
Author: Florian Roth (Nextron Systems)
Date: 2021-08-09
modified:2023-01-23
Tags:
  • -'attack.t1587.001'
  • -'attack.resource-development'
Logsource:
  • product: windows
  • service: msexchange-management
Detection:
  keywords_cmdlet:
    |all:
      -'OabVirtualDirectory'
      -' -ExternalUrl '

  keywords_params:
    - 'eval(request'
    - 'http://f/<script'
    - '"unsafe"};'
    - 'function Page_Load()'
  condition:keywords_cmdlet and keywords_params
Falsepositives:
  -Unlikely
Level: critical