Exchange and Interesting Draft Emails

TempDRK 1 Reputation point
2022-09-26T15:05:33.003+00:00

We are having something interesting happen with our Outlooks.

A string of draft emails will pop up in all users draft boxes. They all have the title "Microsoft Outlook Test message XXXXXXX" The Xs are a random numbers.

Our exchange server is patched up to CU22, and we have AV running, and we are behind a firewall.

I reached out to a cyber contractor we have and they suspected compromise and we went through the list of remediation for malicious activity - checking for webshells, hidden accounts, mailboxes, checking logs for scripts, running the EOMT.ps1 and doing a full scan with our AV. Nothing found, they kept our ticket open and told me to keep an eye on it.

A week later we all have a few more in our draft folders. Thought I would look out a little further for assistance.

244902-snagit-2098.png

Exchange | Exchange Server | Management
{count} votes

2 answers

Sort by: Most helpful
  1. TempDRK 1 Reputation point
    2022-09-30T11:59:36.937+00:00

    We were hit by ProxyShell.

    We have since patched and used mitigation tools.

    0 comments No comments

  2. Joyce Shen - MSFT 16,701 Reputation points
    2022-10-03T07:58:22.607+00:00

    Hi @TempDRK

    Thanks for sharing more information about this issue.

    You may also take a reference at the recent blogs about
    Analyzing attacks using the Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082
    Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server

    Installing the latest SU and mitigation tools are the suggested way by Microsoft.


    If an Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.