I suspect your server has been hacked:
https://www.fireeye.com/blog/threat-research/2021/09/proxyshell-exploiting-microsoft-exchange-servers.html
Have you applied the latest July critical security updates for Exchange?
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Dear sir,
A user found that he has 2 unexpected email in his draft folder today, the message is not belonged to him. Server is Exchange 2019, Outlook is also version 2019.
The email subject name is created by random character: atsgtzpuisiumus , another same email subject is : asdfareafaas.
Inside the email content, both are the same single sentence: "hello darkness my old friend".
It seems that it is an unexpected spam message. May I know how to check why the message can exist inside user of "Draft" folder?
Any suggestion to trace or prevent such message? Or PC has been hacked by virus?
Regards,
Joe Tam
I suspect your server has been hacked:
https://www.fireeye.com/blog/threat-research/2021/09/proxyshell-exploiting-microsoft-exchange-servers.html
Have you applied the latest July critical security updates for Exchange?
Hello,
I have the same drafts from a user, with the same subject "hello darkness my old friend".
Bitdefender antivirus shows nothing, the PC and office suite 2019 are up to date, as well as Exchange 2019.
If you have more info I'm interested.
Best regards
Sami
Here is a blog from Microsoft, it said: ProxyShell vulnerabilities and your Exchange Server
Your Exchange servers are vulnerable if any of the following are true:
In all of the above scenarios, you must install one of latest supported CUs and all applicable SUs to be protected. Any Exchange servers that are not on a supported CU and the latest available SU are vulnerable to ProxyShell and other attacks that leverage older vulnerabilities.
If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.
I too have faced such a problem. If I can get any help from here then I will be grateful.