This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious ASPX File Drop by Exchange
Original Source:
[Sigma source]
Title:
Suspicious ASPX File Drop by Exchange
Status:
test
Description:
Detects suspicious file type dropped by an Exchange component in IIS into a suspicious folder
References:
-https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/
-https://www.gteltsc.vn/blog/canh-bao-chien-dich-tan-cong-su-dung-lo-hong-zero-day-tren-microsoft-exchange-server-12714.html
-https://en.gteltsc.vn/blog/cap-nhat-nhe-ve-lo-hong-bao-mat-0day-microsoft-exchange-dang-duoc-su-dung-de-tan-cong-cac-to-chuc-tai-viet-nam-9685.html
Author:
Florian Roth (Nextron Systems), MSTI (query, idea)
Date:
2022-10-01
modified:
None
Tags:
-'attack.persistence'
-'attack.t1505.003'
Logsource:
product: windows
category: file_event
Detection:
selection:
Image|endswith
:
'\w3wp.exe'
CommandLine|contains
:
'MSExchange'
TargetFilename|contains
:
-'FrontEnd\HttpProxy\'
-'\inetpub\wwwroot\aspnet_client\'
selection_types:
TargetFilename|endswith
:
-'.aspx'
-'.asp'
-'.ashx'
condition
:
all of selection*
Falsepositives:
-Unknown
Level:
high