Forum Discussion

cllee's avatar
cllee
Brass Contributor
Jun 19, 2020

"O365 Suite EX" and "Office365 Shell WCSS-Client" Compromised

Hi,

 

I noticed the following Sign-in events originating from Nigeria, which is not the user location.

Seems like something is compromised.

 

Can I know what is the "O365 Suite UX" and "Office365 Shell WCSS-Client" about?

 

Thanks.

 

 

    • Potter4U's avatar
      Potter4U
      Copper Contributor

      waseem this doesn’t give any proof about the phishing email or says anything about compromised. This just gives definition of the Office365 shell; I believe no one understands the meaning of this alert.

  • Arash0110's avatar
    Arash0110
    Copper Contributor

    cllee, that account has been compromised, for sure, no doubt. We had the same occurrences, and had an user account which didn't have MFA enabled , hacked. And the hacking was done via phishing e-mail. 

  • Unless the user connected via some sort of VPN solution, I'd wager his account has been compromised. Those events correspond to browser logins to the O365 portal/landing page.

    • cllee's avatar
      cllee
      Brass Contributor

      VasilMichev 

      Is there anyway to trace or run audit for whatever action or activities that has been run by that IP address? Thanks.

Resources