We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Exploit:Python/Exchange0502
Aliases: No associated aliases
Summary
Microsoft Defender Antivirus detects and blocks this threat. The detected file will be quarantined.
This generic detection is designed to catch scripts that expose functionality indicating a potential attempt at exploiting a Microsoft Exchange post-authentication vulnerability.
The detection of this threat might indicate the presence of a malware or an actor attempting to gain access to protected resources. It is recommended to investigate the security incident to assess the potential presence of further threats in the network.
Microsoft Defender Antivirus detects and removes this threat as it is detected. If you have cloud-delivered protection, your device gets the latest defenses against new and unknown threats. If you don't have this feature enabled, update your antimalware definitions and run a full scan to remove this threat.
To help reduce the impact of this threat, you can:
-
Immediately isolate the affected device. If malicious code has been launched, it is likely that the device is under complete attacker control.
-
Identify the accounts that have been used on the affected device and consider these accounts compromised. Reset passwords or decommission the accounts.
-
Investigate how the affected endpoint might have been compromised. Check web and email traffic to determine how the malware arrived.
-
Investigate the device timeline for indications of lateral movement activities using one of the compromised accounts. Check for additional tools that attackers might have dropped to enable credential access, lateral movement, and other attack activities.
You can also visit our advanced troubleshooting page or search the Microsoft community for more help.