Microsoft Exchange Servers Still Vulnerable to ProxyShell Exploit | Huntress
ID: 05e831b5-fd27-526e-9640-0b827f90f8ff
STIX ID: report--05e831b5-fd27-526e-9640-0b827f90f8ff
Feed Name: Huntress Blog
Huntress warns of active in-the-wild exploitation of Microsoft Exchange ProxyShell vulnerabilities where attackers implant hidden webshells (including via modified applicationHost.config virtual directories), observed across many servers; the report lists webshell file paths, filesystem locations (ProgramData, C:\Users\All Users, Exchange paths), sample IPs and user-agents, multiple webshell types/TTPs, and recommends urgent patching, removal of webshells, IIS restart, and firewall blocks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
