Hafnium Question

Lyndon 1 Reputation point
2021-03-24T04:51:14.46+00:00

Hi Microsoft Community, may we ask for your help, we already patched our Servers and run the tools from MS and we are fully patched and no malicious files based on Microsoft Safety Scanner. But we can still saw some aspx files and .exe files dropped in our system in our exchange server. The executable files are being blocked by our endpoint protection. May we request for help on what would be our next step for this. Thank you!

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,357 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 142.2K Reputation points MVP
    2021-03-24T11:44:03.203+00:00

    Remove those files?

    If you did a full scan and all the other checks pass, then the system is probably ok, but you will need to determine that.

    If you have any doubts about the server, rebuild it.

    Here is the official guidance:
    https://msrc-blog.microsoft.com/2021/03/16/guidance-for-responders-investigating-and-remediating-on-premises-exchange-server-vulnerabilities/

    1 person found this answer helpful.
    0 comments No comments