EXPL_Exchange_ProxyNotShell_Patterns_CVE_2022_41040_Oct22_1
Description
Detects successful ProxyNotShell exploitation attempts in log files (attempt to identify the attack before the official release of detailed information)
Query · yara
strings:
$sr1 = / \/autodiscover\/autodiscover\.json[^\n]{1,300}owershell/ nocase ascii
$sa1 = " 200 "
$fp1 = " 444 "
$fp2 = " 404 "
$fp2b = " 401 " /* Unauthorized */
$fp3 = "GET /owa/ &Email=autodiscover/autodiscover.json%3F@test.com&ClientId=" ascii /* Nessus */
$fp4 = "@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" ascii /* Nessus */
condition:
$sr1
and 1 of ($sa*)
and not 1 of ($fp*)