Running a PowerEdge Server with Exchange 2016 running as one of the VM's in Hyper-V. The other day my client contacted me and said an email was sent on his behalf and it doesn't appear to be a spoofed email. I checked and someone sent an email on his behalf to the majority of his contacts. This is alarming to say the least.
I noticed a file in Quarantine around the time this happened that was found on the exchange server. File in question C:\ProgramData\ZING\BcByz\mrmrki.aspx. According to Bitdefender, the threat name is Generic.WebShell.X.3CAB5A63. I checked the server endlessly and didn't find anything else that was out of place. Appears to me Bitdefender quarantined a file and prevented further problems. This doesn't explain how the email was sent through.
I ran a scan on my client's desktop and a virus was removed from an email from 2014. Interestingly enough the time it was opened was around the time the suspicious email was sent out from his Outlook. The email also came up on a scan from a person within the company that was included in this attack, someone had sent email on her behalf as well.
Was this attack from the exchange server or client's Outlook? We immediately changed passwords and ran a full scan on the entire network. No other emails were sent since taking these actions.
I'm looking for definite answers to how this happened and look forward to discussing.