Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Play ransomware attacks use a new exploit to bypass ProxyNotShell mitigations on Exchange serversSecurity Affairs

Altszn.com by Altszn.com
December 22, 2022
in Dark Web
0
Play ransomware attacks use a new exploit to bypass ProxyNotShell mitigations on Exchange serversSecurity Affairs
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


Play ransomware attacks target Exchange servers with a new exploit that bypasses Microsoft’s ProxyNotShell mitigations.

Play ransomware operators target Exchange servers using a new exploit chain, dubbed OWASSRF by Crowdstrike, that bypasses Microsoft’s mitigations for ProxyNotShell vulnerabilities.

The ProxyNotShell flaws are:

  • CVE-2022-41040 – Microsoft Exchange Server Elevation of Privilege Vulnerability
  • CVE-2022-41082 – Microsoft Exchange Server Remote Code Execution Vulnerability

they impact Exchange Server 2013, 2016, and 2019, an authenticated attacker can trigger them to elevate privileges to run PowerShell in the context of the system and gain arbitrary or remote code execution on vulnerable servers.

Microsoft addressed both vulnerabilities with the release of Patch Tuesday updates for November 2022 security updates.

The exploit was used by attackers to bypass URL rewrite mitigations for the Autodiscover endpoint implemented by Microsoft in response to ProxyNotShell. Then the ransomware gang leveraged legitimate Plink and AnyDesk executables to maintain access, and performed anti-forensics techniques on the Microsoft Exchange server in an attempt to hide their activity.

“CrowdStrike recently discovered a new exploit method (called OWASSRF) consisting of CVE-2022-41080 and CVE-2022-41082 to achieve remote code execution (RCE) through Outlook Web Access (OWA). The new exploit method bypasses URL rewrite mitigations for the Autodiscover endpoint provided by Microsoft in response to ProxyNotShell.” reads the analysis published by Crowdstrike. “After initial access via this new exploit method, the threat actor leveraged legitimate Plink and AnyDesk executables to maintain access, and performed anti-forensics techniques on the Microsoft Exchange server in an attempt to hide their activity.”

In the attacks investigated by the experts, the threat actor cleared Windows Event Logs on affected backend Exchange servers to prevent investigation on the PowerShell commands used by the attackers.

ProxyNotShell bypass exploit

CrowdStrike security researchers were working to develop proof-of-concept (POC) code in an attempt to reproduce the one used in recent Play ransomware attacks. Simultaneously, a researcher from
HuntressLabs discovered an attacker’s tooling via an open repository and shared it through a MegaUpload link.

179.60.149.28
– Initial access #ProxyNotShell
– Bitsadmin to download tooling (http://179.60.149.28:4427/).
– Installed Screen Connect, ID: b81d2f07c9163bf5, URL: instance-cmjrni-relay.screenconnect[.]com
– Deployed Mimikatz

Crawled and saved their tools, you can access… pic.twitter.com/8vA3LNtpul

— Dray Agha (@Purp1eW0lf) December 14, 2022

The leaked tools included a Python script, poc.py, that when executed, led CrowdStrike researchers to replicate the logs generated in recent Play ransomware attacks.

CrowdStrike researchers Dray Agha replicated the exploit method attack on Exchange systems that were not patched against ProxyNotShell, but could not replicate the attack on patched systems.

Organizations are recommended to apply Microsoft’s November 2022 security updates immediately, disable remote PowerShell for non-administrative users, and to deploy endpoint detection and response (EDR) tools.

Users that cannot apply the KB5019758 patch immediately should disable OWA until the patch can be applied.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ransomware)










Share On








Read More: news.google.com

Tags: affairsAttacksbypassdark webDarknetExchangeExploitmitigationsPlayProxyNotShellransomwareserversSecurity
ADVERTISEMENT

Recent

The Dark Times Are Here. Where Is Bitcoin?

The Dark Times Are Here. Where Is Bitcoin?

June 2, 2025
Monero price eyes $500, but $420 stands as the next key hurdle

Monero price eyes $500, but $420 stands as the next key hurdle

June 2, 2025
AVAX Plunges 9% as Global Economic Tensions Rattle Crypto Markets

AVAX Plunges 9% as Global Economic Tensions Rattle Crypto Markets

June 2, 2025

Categories

  • Bitcoin (4,501)
  • Blockchain (10,743)
  • Crypto (8,682)
  • Dark Web (438)
  • DeFi (8,083)
  • Ethereum (4,531)
  • Metaverse (6,762)
  • Monero (247)
  • NFT (1,071)
  • Solana (4,898)
  • Web3 (19,785)
  • Zcash (457)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    The Dark Times Are Here. Where Is Bitcoin?

    The Dark Times Are Here. Where Is Bitcoin?

    June 2, 2025
    Monero price eyes $500, but $420 stands as the next key hurdle

    Monero price eyes $500, but $420 stands as the next key hurdle

    June 2, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 104,362.00
    • ethereumEthereum (ETH) $ 2,545.10
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.17
    • bnbBNB (BNB) $ 659.89
    • solanaSolana (SOL) $ 153.17
    • usd-coinUSDC (USDC) $ 0.999810
    • dogecoinDogecoin (DOGE) $ 0.191963
    • tronTRON (TRX) $ 0.266450
    • cardanoCardano (ADA) $ 0.674427
    • staked-etherLido Staked Ether (STETH) $ 2,541.02
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 104,244.00
    • hyperliquidHyperliquid (HYPE) $ 33.55
    • suiSui (SUI) $ 3.28
    • wrapped-stethWrapped stETH (WSTETH) $ 3,064.55
    • chainlinkChainlink (LINK) $ 13.73
    • avalanche-2Avalanche (AVAX) $ 20.53
    • stellarStellar (XLM) $ 0.265868
    • bitcoin-cashBitcoin Cash (BCH) $ 399.94
    • the-open-networkToncoin (TON) $ 3.20
    • leo-tokenLEO Token (LEO) $ 8.44
    • shiba-inuShiba Inu (SHIB) $ 0.000013
    • usdsUSDS (USDS) $ 0.999903
    • hedera-hashgraphHedera (HBAR) $ 0.168396
    • moneroMonero (XMR) $ 365.94
    • wethWETH (WETH) $ 2,547.80
    • litecoinLitecoin (LTC) $ 88.11
    • wrapped-eethWrapped eETH (WEETH) $ 2,723.62
    • polkadotPolkadot (DOT) $ 4.04
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • bitget-tokenBitget Token (BGB) $ 4.70
    • pepePepe (PEPE) $ 0.000012
    • pi-networkPi Network (PI) $ 0.644094
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 104,464.00
    • whitebitWhiteBIT Coin (WBT) $ 31.39
    • daiDai (DAI) $ 0.999777
    • aaveAave (AAVE) $ 253.07
    • uniswapUniswap (UNI) $ 6.33
    • bittensorBittensor (TAO) $ 404.65
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • crypto-com-chainCronos (CRO) $ 0.103071
    • aptosAptos (APT) $ 4.77
    • okbOKB (OKB) $ 49.73
    • nearNEAR Protocol (NEAR) $ 2.42
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • jito-staked-solJito Staked SOL (JITOSOL) $ 184.99
    • internet-computerInternet Computer (ICP) $ 4.95
    • ondo-financeOndo (ONDO) $ 0.832369
    • ethereum-classicEthereum Classic (ETC) $ 17.09
    • bitcoinBitcoin (BTC) $ 104,362.00
    • ethereumEthereum (ETH) $ 2,545.10
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.17
    • bnbBNB (BNB) $ 659.89
    • solanaSolana (SOL) $ 153.17
    • usd-coinUSDC (USDC) $ 0.999810
    • dogecoinDogecoin (DOGE) $ 0.191963
    • tronTRON (TRX) $ 0.266450
    • cardanoCardano (ADA) $ 0.674427
    • staked-etherLido Staked Ether (STETH) $ 2,541.02
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 104,244.00
    • hyperliquidHyperliquid (HYPE) $ 33.55
    • suiSui (SUI) $ 3.28
    • wrapped-stethWrapped stETH (WSTETH) $ 3,064.55
    • chainlinkChainlink (LINK) $ 13.73
    • avalanche-2Avalanche (AVAX) $ 20.53
    • stellarStellar (XLM) $ 0.265868
    • bitcoin-cashBitcoin Cash (BCH) $ 399.94
    • the-open-networkToncoin (TON) $ 3.20
    • leo-tokenLEO Token (LEO) $ 8.44
    • shiba-inuShiba Inu (SHIB) $ 0.000013
    • usdsUSDS (USDS) $ 0.999903
    • hedera-hashgraphHedera (HBAR) $ 0.168396
    • moneroMonero (XMR) $ 365.94
    • wethWETH (WETH) $ 2,547.80
    • litecoinLitecoin (LTC) $ 88.11
    • wrapped-eethWrapped eETH (WEETH) $ 2,723.62
    • polkadotPolkadot (DOT) $ 4.04
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • bitget-tokenBitget Token (BGB) $ 4.70
    • pepePepe (PEPE) $ 0.000012
    • pi-networkPi Network (PI) $ 0.644094
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 104,464.00
    • whitebitWhiteBIT Coin (WBT) $ 31.39
    • daiDai (DAI) $ 0.999777
    • aaveAave (AAVE) $ 253.07
    • uniswapUniswap (UNI) $ 6.33
    • bittensorBittensor (TAO) $ 404.65
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • crypto-com-chainCronos (CRO) $ 0.103071
    • aptosAptos (APT) $ 4.77
    • okbOKB (OKB) $ 49.73
    • nearNEAR Protocol (NEAR) $ 2.42
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • jito-staked-solJito Staked SOL (JITOSOL) $ 184.99
    • internet-computerInternet Computer (ICP) $ 4.95
    • ondo-financeOndo (ONDO) $ 0.832369
    • ethereum-classicEthereum Classic (ETC) $ 17.09