# Detection and Response for ProxyShell Activity

**URL:** <https://discuss.elastic.co/t/detection-and-response-for-proxyshell-activity/282407>\
**Category:** Elastic Security\
**Created:** [August 24, 2021, 7:58pm UTC](https://discuss.elastic.co/t/detection-and-response-for-proxyshell-activity/282407 "2021-08-24T19:58:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![variable](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/variable/32/118277_2.png) [@variable](https://discuss.elastic.co/u/variable)\
**Post date:** [August 24, 2021, 7:58pm UTC](https://discuss.elastic.co/t/detection-and-response-for-proxyshell-activity/282407/1 "2021-08-24T19:58:56Z")

</div>

# Detection and Response for ProxyShell Activity

## Executive Summary

On August 21, 2021, the Cybersecurity and Infrastructure Security Agency (CISA) released an urgent [notice](https://us-cert.cisa.gov/ncas/current-activity/2021/08/21/urgent-protect-against-active-exploitation-proxyshell) related to the exploitation of ProxyShell vulnerabilities ([CVE-2021-31207](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-31207), [CVE-2021-34473](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34473), [CVE-2021-34523](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34523)). By chaining these vulnerabilities together, threat actors are compromising unpatched Microsoft Exchange servers and gaining footholds in enterprise networks. [Security vendors](https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lockfile-ransomware-new-petitpotam-windows) and [researchers](https://twitter.com/KyleHanslovan/status/1428804893423382532?s=20) are also observing post-exploitation behaviors such as deploying ransomware to victim environments. The Elastic Security Intelligence & Analytics team provides detection logic to identify this activity, as well as observations about exploitation in the wild.

## Details

On August 21, 2021, the Cybersecurity and Infrastructure Security Agency (CISA) released an urgent [notice](https://us-cert.cisa.gov/ncas/current-activity/2021/08/21/urgent-protect-against-active-exploitation-proxyshell) related to the exploitation of ProxyShell vulnerabilities ([CVE-2021-34473](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34473), [CVE-2021-34523](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34523), and [CVE-2021-31207](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-31207)). Microsoft has issued several patches for these vulnerabilities earlier in the year, however inconsistent adoption of those patches has left some infrastructure exposed. The threat of exploitation is more significant due to combining exploits for one or more vulnerabilities.

As reported by [Symantec](https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lockfile-ransomware-new-petitpotam-windows) and other [security service providers](https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit), adversaries exploit these vulnerabilities and attempt to install webshells - web content, served on-demand, that functions similarly to backdoors. Using these web shells, adversaries inherit the privilege level of the Exchange IIS web server to perform reconnaissance, harvest credentials, and pursue post-exploitation behavior such as installing ransomware.

Elastic observed unusual descendant processes (`cmd.exe` and `poweshell.exe`) of the Exchange IIS webserver process (`w3wp.exe`) that involved notable remote network indicators to high-numbered ports (Figure 1).

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6f5a86a9efd3ceb2c341fe2fc35877ec1ea7b840.png)  
_Figure 1 - Process ancestry of Exchange server exploitation_

Our observations have been independently corroborated by [others](https://twitter.com/VirITeXplorer/status/1429803049489424391?s=20) in the community as malicious. While a complete understanding of served content is unknown, it appears that requests are being evaluated

### Overview

The key takeaways of this analysis are as follows:

- Significant rise in exploitation of Exchange servers in recent weeks related to the ProxyShell exploit
- National Institute of Standards and Technology (NIST) assigned a critical [CVSS score](https://www.first.org/cvss/v3.1/specification-document) of 8.8 out of 10 based on remote code execution without authentication ([CVE-2021-31207](https://nvd.nist.gov/vuln/detail/CVE-2021-31207))
- National Institute of Standards and Technology (NIST) assigned a critical [CVSS score](https://www.first.org/cvss/v3.1/specification-document) of 10 out of 10 based on remote code execution without authentication ([CVE-2021-34473](https://nvd.nist.gov/vuln/detail/CVE-2021-34473))
- National Institute of Standards and Technology (NIST) assigned a critical [CVSS score](https://www.first.org/cvss/v3.1/specification-document) of 9.8 out of 10 based on remote code execution without authentication ([CVE-2021-34523](https://nvd.nist.gov/vuln/detail/CVE-2021-34523))
- These vulnerabilities affect on-premises Exchange servers which are self-managed

### Timeline of Events

The events of this campaign were observed in the following order.

- May 11, 20212 - Microsoft released Exchange server patch ([CVE-2021-31207](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-31207))
- July 13, 2021 - Microsoft released additional Exchange server patches ([CVE-2021-34473](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34473), [CVE-2021-34523](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34523))
- August 6, 2021 - ProxyShell [proof-of-concept (POC) code](https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1) released
- August 13, 2021 - Large uptick in Exchange server compromises reported by community
- August 18, 2021 - Elastic first observes ProxyShell activity

## Impact

Microsoft asserts that these vulnerabilities affect all on-premises Exchange servers (Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019). Exchange Online is not affected.

Notably, the initial attack requires on-premises Exchange servers to be accessible to the public Internet via port 443. Attackers with access to enterprises where Exchange servers are internally accessible may be able to exploit unpatched vulnerabilities related to this activity.

The ProxyShell exploit chain leverages multiple tactics and techniques categorized by the MITRE ATT&CK® framework:

- Tactics
  - [Persistence](https://attack.mitre.org/tactics/TA0003/)

- Techniques/Sub-Techniques
  - [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190/)
  - [Server Software Component: Web Shell](https://attack.mitre.org/techniques/T1505/003/)

## Detection

Elastic recommends leveraging the below logic to aid in the detection of adversary activity within your environment. Additionally, the provided defensive recommendations may be used to harden and defend vulnerable systems from the successful exploitation of this campaign.

### Detection logic

On August 24, Elastic released guidance describing existing and new detection logic that can be used to identify this cluster of activity (ProxyShell):

- Existing logic:
  - [Exporting Exchange Mailbox via PowerShell](https://github.com/elastic/detection-rules/blob/a0e86e20d6ad039dfe4446b28f3c29642b50385c/rules/windows/collection_email_powershell_exchange_mailbox.toml)

- New logic:
  - [Webshell Detection](https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_webshell_detection.toml)

### Defensive Recommendations

1. Review and ensure that you have deployed the latest Microsoft Security Updates for Exchange Server, consider other [recommendations](https://www.microsoft.com/security/blog/2020/06/24/defending-exchange-servers-under-attack/) from Microsoft for Exchange hardening
2. Leverage [Auditbeat’s File Integrity Monitoring](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html) function to identify changes to the Exchange configuration file and Internet directories located at `C:\Windows\System32\inetsrv\Config\applicationHost.config` and `C:\inetpub\wwwroot\`
3. Maintain backups of your critical systems to aid in quick recovery
4. Perform routine vulnerability scans of your systems and patch identified vulnerabilities
5. Review and [implement](https://www.elastic.co/guide/en/security/current/rules-ui-management.html) the above detection logic within your environment using technology such as the Elastic Endpoint, Winlogbeat, Filebeat, Packetbeat, or Network Security Monitoring (NSM) platforms such as Zeek or Suricata
6. Block network traffic from malicious IP addresses associated with ProxyShell activity

## References

1. Urgent: Protect Against Active Exploitation of ProxyShell Vulnerabilities

2. CVE-2021-31207 | Microsoft Server Remote Code Execution Vulnerability

3. CVE-2021-34473 | Microsoft Server Remote Code Execution Vulnerability

4. CVE-2021-34523 | Microsoft Server Remote Code Execution Vulnerability

5. LockFile: Ransomware Uses PetitPotam Exploit to Compromise Windows Domain Controllers

6. Microsoft Exchange Servers Still Vulnerable to ProxyShell Exploit

## Indicators

Table 1 describes atomic indicators of compromise (IOCs) observed in this intrusion set. IOCs observed by Elastic have been included for the community, and don't represent all IOCs associated with ProxyShell or ProxyShell-inspired intrusions.

| Artifact | Note |
| --- | --- |
| 45.91.83[.]176 | Staging site, hosts payload file used in this activity cluster |
| _Table 1 - Indicators of Compromise_ | |

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2021, 7:59pm UTC](https://discuss.elastic.co/t/detection-and-response-for-proxyshell-activity/282407/2 "2021-09-21T19:59:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
