hafnium question

gman 21 Reputation points
2021-03-05T14:24:41.06+00:00

when running the hafnium powershell script on our exchange 2013 server, the only thing returned was two entries in autodiscover.

each ended with: the email address cannot be found.

2021-03-03T11:32:23.754Z,ab20f7df-07ff-4abf-bc47-ce9e31fea8bd,15,0,1395,0,,Negotiate,true,NT AUTHORITY\SYSTEM,,ExchangeServicesClient/0.0.0.0,86.105.18.116,JFIEX2013P,MYEXCHANGE.MYDOMAIN.COM,POX,200,500,0,0,1,,,,,GlobalThrottlingPolicy_f9fb2403-54c7-412d-b51b-7f13cdaa45cb,,,1,3,0,3,2,,10,ADSessionSettingsFromAddress=0;ADRecipientSessionFindBySid=0;Caller=null;ResolveMethod=Unknown;RequestedRecipient=null;RequestedUser=administrator@Mydomain.com;S:ServiceCommonMetadata.RequestSize=347;S:WLM.Bal=300000;S:WLM.BT=Ews;S:BudgetMetadata.MaxConn=27;S:BudgetMetadata.MaxBurst=300000;S:BudgetMetadata.BeginBalance=300000;S:BudgetMetadata.Cutoff=3000000;S:BudgetMetadata.RechargeRate=900000;S:BudgetMetadata.IsServiceAct=False;S:BudgetMetadata.LiveTime=00:00:00;S:BudgetMetadata.EndBalance=300000;Dbl:WLM.TS=10;I32:ADS.C[ad-2]=2;F:ADS.AL[ad-2]=2.5936;I32:ATE.C[dc1.mydomain.com]=1;F:ATE.AL[dc1.mydomain.com]=0;I32:ADS.C[dc1]=1;F:ADS.AL[dc1]=2.3683,,message=The email address can't be found.;

is this false positve, indication of scan or what? all other tests showed no issue.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,362 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,899 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Joyce Shen - MSFT 16,646 Reputation points
    2021-03-08T02:31:32.48+00:00

    Hi @gman

    Please also check if you see any other suspicious activity like ECP/OWA/OAB or evidence of the other CVE's being hit then collect the following data from the impacted server(s):
    C:\inetpub\wwwroot\aspnet_client\ *.aspx
    C:\inetpub\wwwroot\aspnet_client\system_web\
    %ExchangeInstallPath%\FrontEnd\HttpProxy\OWA\Auth\
    The log output from the Test-ProxyLogon Script

    Detailed information refer to this Scan Exchange log files for indicators of compromise

    Make sure you have upgraded your Exchange server to the latest CU version and have installed the security patch, this method is the only complete mitigation and has no impact to functionality.


    If an Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.
     

    0 comments No comments

  2. Andy David - MVP 142.3K Reputation points MVP
    2021-03-08T12:53:49.197+00:00