diff --git a/detections/experimental/endpoint/microsoft_exchange_mailbox_replication_service_writing_active_server_pages.yml b/detections/experimental/endpoint/microsoft_exchange_mailbox_replication_service_writing_active_server_pages.yml new file mode 100644 index 0000000000..c41f9440b6 --- /dev/null +++ b/detections/experimental/endpoint/microsoft_exchange_mailbox_replication_service_writing_active_server_pages.yml @@ -0,0 +1,100 @@ +name: Microsoft Exchange Mailbox Replication service writing Active Server Pages +id: 985f322c-57a5-11ec-b9ac-acde48001122 +version: 1 +date: '2021-12-07' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: 'The following query identifies suspicious .aspx created in 3 paths identified + by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM + group and recently disclosed vulnerablity named ProxyShell. Paths include: `\HttpProxy\owa\auth\`, + `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. The analytic is limited to process name MSExchangeMailboxReplication.exe, which typically does not write .aspx files to disk. + Upon triage, the suspicious + .aspx file will likely look obvious on the surface. inspect the contents for script + code inside. Identify additional log sources, IIS included, to review source and + other potential exploitation. It is often the case that a particular threat is only + applicable to a specific subset of systems in your environment. Typically analytics + to detect those threats are written without the benefit of being able to only target + those systems as well. Writing analytics against all systems when those behaviors + are limited to identifiable subsets of those systems is suboptimal. Consider the + case ProxyShell vulnerability on Microsoft Exchange Servers. With asset information, + a hunter can limit their analytics to systems that have been identified as Exchange + servers. A hunter may start with the theory that the exchange server is communicating + with new systems that it has not previously. If this theory is run against all publicly + facing systems, the amount of noise it will generate will likely render this theory + untenable. However, using the asset information to limit this analytic to just the + Exchange servers will reduce the noise allowing the hunter to focus only on the + systems where this behavioral change is relevant.' +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + where Processes.process_name=MSExchangeMailboxReplication.exe by _time span=1h Processes.process_id Processes.process_name Processes.process_guid + Processes.dest | `drop_dm_object_name(Processes)` | join process_guid, _time [| + tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", + "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx" + by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name + Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time + file_name file_path process_name process_path process process_guid] | dedup file_create_time + | table dest file_create_time, file_name, file_path, process_name | `microsoft_exchange_mailbox_replication_service_writing_active_server_pages_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` + node. +known_false_positives: The query is structured in a way that `action` (read, create) + is not defined. Review the results of this query, filter, and tune as necessary. + It may be necessary to generate this query specific to your endpoint product. +references: + - https://redcanary.com/blog/blackbyte-ransomware/ +tags: + analytic_story: + - ProxyShell + - Ransomware + confidence: 90 + context: + - Source:Endpoint + - Stage:Exploitation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: A file - $file_name$ was written to disk that is related to IIS exploitation + related to ProxyShell. Review further file modifications on endpoint + $dest$ by user $user$. + mitre_attack_id: + - T1505 + - T1505.003 + - T1190 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: file_name + type: File Name + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Filesystem.file_path + - Filesystem.process_id + - Filesystem.file_name + - Filesystem.file_hash + - Filesystem.user + - Filesystem.process_guid + - Processes.process_name + - Processes.process_id + - Processes.process_name + - Processes.process_guid + risk_score: 81 + security_domain: endpoint + + \ No newline at end of file