Detects Suspicious POST Requests Targeting Microsoft Exchange OWA/ECP Paths
Flags POST traffic to Exchange OWA/ECP-related URLs with specific client and user-agent indicators consistent with exploitation attempts.
FreeUnreviewedSigmahighv1
detects-suspicious-post-requests-targeting-microsoft-exchange-owa-ecp-paths-67bce556
title: Detects Suspicious POST Requests Targeting Microsoft Exchange OWA/ECP Paths
id: 11797fde-9c4f-4bf7-a3f0-1795dc7d9432
status: test
description: This rule identifies potential exploitation activity by flagging HTTP POST requests whose URL paths and user agents match patterns associated with Exchange OWA and ECP components. Attackers often use scripted requests or custom clients to probe and exploit exposed Exchange endpoints, so correlating these requests in webserver logs can help surface initial access attempts. It relies on telemetry fields for HTTP method, request URI query/contents, and user-agent strings as recorded by the webserver logs.
references:
- https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
- https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/HAFNIUM/web_exchange_exploitation_hafnium.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-03-03
modified: 2023-01-02
tags:
- attack.initial-access
- attack.t1190
- attack.g0125
- detection.emerging-threats
logsource:
category: webserver
detection:
selection_1:
cs-method: POST
cs-uri-query|contains: /owa/auth/Current/themes/resources/
selection_2:
cs-method: POST
cs-uri-query|contains: /owa/auth/Current/
cs-user-agent:
- DuckDuckBot/1.0;+(+http://duckduckgo.com/duckduckbot.html)
- facebookexternalhit/1.1+(+http://www.facebook.com/externalhit_uatext.php)
- Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html)
- Mozilla/5.0+(compatible;+Bingbot/2.0;++http://www.bing.com/bingbot.htm)
- Mozilla/5.0+(compatible;+Googlebot/2.1;++http://www.google.com/bot.html
- Mozilla/5.0+(compatible;+Konqueror/3.5;+Linux)+KHTML/3.5.5+(like+Gecko)+(Exabot-Thumbnails)
- Mozilla/5.0+(compatible;+Yahoo!+Slurp;+http://help.yahoo.com/help/us/ysearch/slurp)
- Mozilla/5.0+(compatible;+YandexBot/3.0;++http://yandex.com/bots)
- Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36
selection_3:
cs-uri-query|contains: /ecp/
cs-method: POST
cs-user-agent:
- ExchangeServicesClient/0.0.0.0
- python-requests/2.19.1
- python-requests/2.25.1
selection_4:
cs-uri-query|contains:
- /aspnet_client/
- /owa/
cs-method: POST
cs-user-agent:
- antSword/v2.1
- Googlebot/2.1+(+http://www.googlebot.com/bot.html)
- Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html)
selection_5:
cs-uri-query|contains:
- /owa/auth/Current/
- /ecp/default.flt
- /ecp/main.css
cs-method: POST
selection_6:
cs-method: POST
cs-uri-query|contains|all:
- /ecp/
- .js
condition: 1 of selection_*
falsepositives:
- Legitimate access to other web applications that use the same folder names as Exchange (e.g. owa, ecp) but are not Microsoft Exchange related
level: high
license: DRL-1.1
related:
- id: 67bce556-312f-4c81-9162-c3c9ff2599b2
type: derived
What it detects
This rule identifies potential exploitation activity by flagging HTTP POST requests whose URL paths and user agents match patterns associated with Exchange OWA and ECP components. Attackers often use scripted requests or custom clients to probe and exploit exposed Exchange endpoints, so correlating these requests in webserver logs can help surface initial access attempts. It relies on telemetry fields for HTTP method, request URI query/contents, and user-agent strings as recorded by the webserver logs.
Known false positives
- Legitimate access to other web applications that use the same folder names as Exchange (e.g. owa, ecp) but are not Microsoft Exchange related
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.