Office 365 - Zero-hour auto purge (ZAP) not work and pc was infected (not detected by Windows Defend

Contributor

Hi,

this is just to alert MS Security Team that the 'ZAP' not worked as expected and MS Antispam services also failed to detect a email pishing. Few minutes ago a customer send me a whastapp image about outlook shows a msg about 'c:\users\aline\AppData\localpixelcryto\pixelcryptoa.exe' and also about 'c:\users\aline\AppData\localpixelcryto\pixelcryptob.exe'; that msg comes with a '.doc' attachment.

Using the 'Security and Compliance Center' we cannot create alert to MS since shows that msg ID was invalid, until we copy all headers and put on the 'MS Connectivity Analyzer/Message Analyzer' website and then use the header 'X-MS-Exchange-Organization-Network-Message-Id' = reported fine!

The FOREFRONT failed to protect. Maybe MS dev team should use some filter when Word, Excel and PowerPoint tries to open a file, before open itself, try to scan it!!

 

The Windows Defender failed to detect file on Windows, maybe regkeys to 'run' when starts should be more protected because due to some applications we need put user as 'local admin'.

 

The good news was that without restart the PC, the Sophos Endpoint was installed, malware detected and fixed reg keys also. After restart PC and open MS Outlook again we realize that this msg has 'zero-hour auto purge text file' - maybe that delay on detect could be infect more user around world.

---

Usefull links:

https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/zero-hour-auto-purge

https://docs.microsoft.com/en-us/microsoft-365/compliance/view-email-security-reports#threat-protect...

* appear to shows only past 24 hours - not realtime.

---

Usefull info about msg

---

X-MS-Exchange-Organization-Network-Message-Id213b71ad-cdb7-428b-9e6e-08d746aa0404
X-Forefront-Antispam-ReportCIP:54.187.208.83;IPV:NLI;CTRY:US;EFV:NLI;SFV:NSPM;SFS:(428003)(149574003)(189003)(199004)(956004)(568964002)(476003)(33964004)(336012)(26005)(486006)(3672435006)(126002)(58800400005)(564344004)(9686003)(31686004)(2476003)(5660300002)(6266002)(356004)(3480700005)(2160300002)(16003)(6706004)(6916009)(2351001)(16586007)(246002)(74316002)(7636002)(7596002)(305945005)(5000100001)(7116003)(31696002)(8676002)(21480400003)(21440400002)(1096003)(4300700001)(1560700002)(22186003)(71190400001)(86362001)(5024004)(14444005)(77360400006)(142963005);DIR:INB;SFP:;SCL:1;SRVR:RO1P152MB0811;H:m3.pauspam.net;FPR:;SPF:None;LANG:en;PTR:m3.pauspam.net;MX:1;A:1;

---

CryptoA-01.pngCryptoA-02.pngCryptoA-03-sophos.PNGCryptoA-04-sophos.PNGCryptoA-05-ExchMessageTracking.png

---

---

---

---

0 Replies