Application Event ID 1309 ASP.Net 4.0.30319.0 Exchange Server 2019 /owa/auth/x.js

Jon Westgate 1 Reputation point
2022-03-30T14:37:42.76+00:00

I'm getting this in my Event Log and the server is very slow (almost unusable)
I rebooted it and looked in the event log I'm seeing this and almost identical errors but showing from different hosts (IP's)

Event code: 3005
Event message: An unhandled exception has occurred.
Event time: 30/03/2022 10:59:54
Event time (UTC): 30/03/2022 09:59:54
Event ID: b2395ea0a7c6495e8f512a8ce959e8ec
Event sequence: 2
Event occurrence: 1
Event detail code: 0

Application information:
Application domain: /LM/W3SVC/1/ROOT/owa-1-132931077644820598
Trust level: Full
Application Virtual Path: /owa
Application Path: C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\HttpProxy\owa\
Machine name: BH-EX

Process information:
Process ID: 11820
Process name: w3wp.exe
Account name: NT AUTHORITY\SYSTEM

Exception information:
Exception type: ArgumentException
Exception message: Invalid input value
Parameter name: input
at Microsoft.Exchange.Data.ApplicationLogic.Cafe.BackEndServer.FromString(String input)
at Microsoft.Exchange.HttpProxy.OwaResourceProxyRequestHandler.ResolveAnchorMailbox()
at Microsoft.Exchange.HttpProxy.ProxyRequestHandler.InternalBeginCalculateTargetBackEnd(AnchorMailbox& anchorMailbox)
at Microsoft.Exchange.HttpProxy.ProxyRequestHandler.<BeginCalculateTargetBackEnd>b__278_0()
at Microsoft.Exchange.Common.IL.ILUtil.DoTryFilterCatch(Action tryDelegate, Func2 filterDelegate, Action1 catchDelegate)
at Microsoft.Exchange.HttpProxy.ProxyRequestHandler.CallThreadEntranceMethod(Action method)

Request information:
Request URL: https://<ip address>:443/owa/auth/x.js
Request path: /owa/auth/x.js
User host address: <ip address>
User:
Is authenticated: False
Authentication Type:
Thread account name: NT AUTHORITY\SYSTEM

Thread information:
Thread ID: 23
Thread account name: NT AUTHORITY\SYSTEM
Is impersonating: False
Stack trace: at Microsoft.Exchange.Data.ApplicationLogic.Cafe.BackEndServer.FromString(String input)
at Microsoft.Exchange.HttpProxy.OwaResourceProxyRequestHandler.ResolveAnchorMailbox()
at Microsoft.Exchange.HttpProxy.ProxyRequestHandler.InternalBeginCalculateTargetBackEnd(AnchorMailbox& anchorMailbox)
at Microsoft.Exchange.HttpProxy.ProxyRequestHandler.<BeginCalculateTargetBackEnd>b__278_0()
at Microsoft.Exchange.Common.IL.ILUtil.DoTryFilterCatch(Action tryDelegate, Func2 filterDelegate, Action1 catchDelegate)
at Microsoft.Exchange.HttpProxy.ProxyRequestHandler.CallThreadEntranceMethod(Action method)

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,009 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Kael Yao-MSFT 33,856 Reputation points Microsoft Vendor
    2022-03-31T06:34:21.843+00:00

    Hi @Jon Westgate

    These events seem to be related to Hafnium attack.
    Here are several links for your reference:
    bad actors targeted exchange- /owa/auth/x.js
    Suspicious events

    What is the current CU and SU version of your Exchange server?
    Please download and run the HealthChecker script to check the result.

    If you haven't upgraded to the latest CU and installed the latest SU, please consider upgrading for security.
    Exchange Server 2019 builds

    Also follow the suggestions in this link: Guidance for responders: Investigating and remediating on-premises Exchange Server vulnerabilities


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.