Skip to content

Hide Navigation Hide TOC

ProxyLogon MSExchange OabVirtualDirectory (550d3350-bb8a-4ff3-9533-2ba533f4a1c0)

Detects specific patterns found after a successful ProxyLogon exploitation in relation to a Commandlet invocation of Set-OabVirtualDirectory

Cluster A Galaxy A Cluster B Galaxy B Level
ProxyLogon MSExchange OabVirtualDirectory (550d3350-bb8a-4ff3-9533-2ba533f4a1c0) Sigma-Rules Malware - T1587.001 (212306d8-efa4-44c9-8c2d-ed3d2e224aa0) Attack Pattern 1
Develop Capabilities - T1587 (edadea33-549c-4ed1-9783-8f5a5853cbdf) Attack Pattern Malware - T1587.001 (212306d8-efa4-44c9-8c2d-ed3d2e224aa0) Attack Pattern 2