Forum Discussion
cllee
Jun 19, 2020Brass Contributor
"O365 Suite EX" and "Office365 Shell WCSS-Client" Compromised
Hi,
I noticed the following Sign-in events originating from Nigeria, which is not the user location.
Seems like something is compromised.
Can I know what is the "O365 Suite UX" and "Office365 Shell WCSS-Client" about?
Thanks.
- waseemCopper Contributor“Office 365 Shell WCSS-Client is the browser code that runs whenever a user navigates to (most) Office365 applications in the browser. The shell, also known as the suite header, is shared code that loads as part of almost all Office365 workloads, including SharePoint, OneDrive, Outlook, Yammer, and many more.
https://www.jasonfritts.me/2019/01/05/what-is-office-365-shell-wcss-client/ - NatashaT35Copper Contributor
Arash0110 Hi how did you establish account was compromised by phishing email?
Unless the user connected via some sort of VPN solution, I'd wager his account has been compromised. Those events correspond to browser logins to the O365 portal/landing page.
- clleeBrass Contributor
Is there anyway to trace or run audit for whatever action or activities that has been run by that IP address? Thanks.
- engoelhamyCopper Contributor
cllee using Microsoft cloud app security