Microsoft Exchange exploitation attempt via suspicious POST requests in web server logs

Flags POST traffic to Exchange OWA/ECP-related URLs with specific client and user-agent indicators consistent with exploitation attempts.

FreeReviewedSigma · High · v5
Category
webserver
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-03-03
Updated
2026-07-31
title: Microsoft Exchange exploitation attempt via suspicious POST requests in web server logs
id: 11797fde-9c4f-4bf7-a3f0-1795dc7d9432
status: test
description: This rule flags HTTP POST activity against Microsoft Exchange-related paths (such as /owa/ and /ecp/) combined with specific user agents and query components. Attackers may use crafted requests to exploit exposed Exchange endpoints for initial access or remote exploitation. The detection relies on web server request telemetry, matching the HTTP method, URI query/content patterns, and exact or listed User-Agent strings.
references:
  - https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
  - https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/HAFNIUM/web_exchange_exploitation_hafnium.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-03-03
modified: 2023-01-02
tags:
  - attack.initial-access
  - attack.t1190
  - attack.g0125
  - detection.emerging-threats
logsource:
  category: webserver
detection:
  selection_1:
    cs-method: POST
    cs-uri-query|contains: /owa/auth/Current/themes/resources/
  selection_2:
    cs-method: POST
    cs-uri-query|contains: /owa/auth/Current/
    cs-user-agent:
      - DuckDuckBot/1.0;+(+http://duckduckgo.com/duckduckbot.html)
      - facebookexternalhit/1.1+(+http://www.facebook.com/externalhit_uatext.php)
      - Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html)
      - Mozilla/5.0+(compatible;+Bingbot/2.0;++http://www.bing.com/bingbot.htm)
      - Mozilla/5.0+(compatible;+Googlebot/2.1;++http://www.google.com/bot.html
      - Mozilla/5.0+(compatible;+Konqueror/3.5;+Linux)+KHTML/3.5.5+(like+Gecko)+(Exabot-Thumbnails)
      - Mozilla/5.0+(compatible;+Yahoo!+Slurp;+http://help.yahoo.com/help/us/ysearch/slurp)
      - Mozilla/5.0+(compatible;+YandexBot/3.0;++http://yandex.com/bots)
      - Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36
  selection_3:
    cs-uri-query|contains: /ecp/
    cs-method: POST
    cs-user-agent:
      - ExchangeServicesClient/0.0.0.0
      - python-requests/2.19.1
      - python-requests/2.25.1
  selection_4:
    cs-uri-query|contains:
      - /aspnet_client/
      - /owa/
    cs-method: POST
    cs-user-agent:
      - antSword/v2.1
      - Googlebot/2.1+(+http://www.googlebot.com/bot.html)
      - Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html)
  selection_5:
    cs-uri-query|contains:
      - /owa/auth/Current/
      - /ecp/default.flt
      - /ecp/main.css
    cs-method: POST
  selection_6:
    cs-method: POST
    cs-uri-query|contains|all:
      - /ecp/
      - .js
  condition: 1 of selection_*
falsepositives:
  - Legitimate access to other web applications that use the same folder names as Exchange (e.g. owa, ecp) but are not Microsoft Exchange related
level: high
license: DRL-1.1
related:
  - id: 67bce556-312f-4c81-9162-c3c9ff2599b2
    type: derived