6.8 KiB
Breach Check + Remediation: Orders@valleywideplastering.com
Date: 2026-07-16
Tenant: Valleywide Plastering (valleywideplastering.com, 5c53ae9f-7071-4248-b834-8685b646450f)
Subject: Orders@valleywideplastering.com
Tool: ComputerGuru remediation app suite — tiers used: Security Investigator bfbc12a4 (Graph reads), Investigator-EXO (Exchange reads), User Manager 64fac46b (session revoke), Tenant Admin 709e6eed (device deletion)
Scope: included remediation (device deletion + session revoke, confirmed by Winter in Discord)
Requested by: Winter (Discord @winterguru), thread 1527356833902362654
Summary
- Confirmed AiTM token-theft compromise on 2026-07-02 17:20 UTC — sign-in from datacenter IP 172.245.92.208 (ColoCrossing) to Microsoft Intune Enrollment with "MFA requirement satisfied by claim in the token" (replayed session token; CA MFA passed on the stolen claim).
- Attacker registered persistence device
DESKTOP-YQL6X9KXat 2026-07-02 17:21:00Z (Entra workplace join under this account). - Partial remediation already occurred 2026-07-06 (~16:33–16:40 UTC): password reset twice + StsRefreshTokenValidFrom bumped via ComputerGuru Tenant Admin; MFA info updated 16:45 UTC.
- Rogue device was still registered and ENABLED as of 2026-07-16 — deleted this session. Sessions re-revoked.
- Mailbox itself is clean: no rules (incl. hidden), no forwarding, no delegations, no OAuth grants, no outbound abuse.
- Tenant sweep of attacker IP: only orders@ was touched — no other VWP users saw sign-ins from 172.245.92.208 (30d window).
Target details
| Field | Value |
|---|---|
| UPN | Orders@valleywideplastering.com |
| Object ID | 3739c527-f156-49b7-8779-a19033564a0f |
| Account Enabled | true |
| Created | 2023-03-17T21:54:40Z |
| Last Password Change | 2026-07-06T16:39:58Z |
Per-check findings
1. Inbox rules (Graph)
0 rules.
2. Mailbox forwarding / settings
No forwarding configured (ForwardingAddress / ForwardingSmtpAddress empty). No auto-reply anomalies.
3. Exchange REST (hidden rules, delegates, SendAs, Get-Mailbox)
0 hidden inbox rules. No non-SELF mailbox permissions. No non-SELF SendAs. No mailbox-level forwarding.
4. OAuth consents + app role assignments
0 OAuth grants, 0 app role assignments.
5. Authentication methods
3 methods, all outside the attack window (benign):
- passwordAuthenticationMethod
- microsoftAuthenticatorAuthenticationMethod — "iPhone 11" (user's phone)
- windowsHelloForBusinessAuthenticationMethod — created 2025-06-24T14:24:00Z (predates incident by a year)
6. Sign-ins (30d, interactive)
127 sign-ins. Dominant IP 4.18.160.106 (124 — office egress, Leesburg geo). Error-code mix normal (50072/50076/50079 MFA interrupts, 50140 KMSI).
- 7x 50126 (bad password) on 2026-07-06 16:35–22:16 UTC from the office IP = user retrying the OLD password during/after the 7/6 admin reset. Benign.
- 2x from 172.245.92.208 (ColoCrossing datacenter, LA geo) on 2026-07-02 17:20 UTC — Microsoft Authentication Broker → Microsoft Intune Enrollment, Chrome 150,
50199then0(success). "MFA requirement satisfied by claim in the token" = token replay. CA "Require MFA for all users" = success (satisfied by stolen claim); "Block Sign-ins Outside US" notApplied (IP geolocates US). - The "non-US" flag in the script summary was a false positive: a 500142 redemption-continuation event from the office IP with no geo populated.
7. Directory audits
15 events (30d):
- 2026-07-02 17:21:01Z — "Add registered users to device" + "Add registered owner to device" via Device Registration Service (attacker device join).
- 2026-07-06 16:33 + 16:39 UTC — two password resets + StsRefreshTokenValidFrom updates via ComputerGuru Tenant Admin / User Manager (prior remediation).
- 2026-07-06 16:45 UTC — Azure MFA StrongAuthenticationService "Update user" (MFA info re-registration after reset).
8. Risky users / risk detections
riskyUser endpoint returned 403 Forbidden — Security Investigator consent on this tenant is PARTIAL (missing User.Read.All, Sites.Read.All; IdentityRiskyUser likely part of the stale grant). riskDetections returned 0. Sign-in risk fields on the attack events are "hidden" (license/scope).
9. Sent items (recent 25)
Normal business traffic (orders to suppliers, internal scheduling). No blast patterns, no unusual externals.
10. Deleted items (recent 25)
Normal. No deleted security alerts or MFA notifications.
Suspicious items
- AiTM token replay from 172.245.92.208 (ColoCrossing hosting) on 2026-07-02 17:20 UTC.
- Attacker-registered Entra device
DESKTOP-YQL6X9KX(deviceId 850e5a7e-c7bb-4d65-9bc4-740e11a61ebc, objectId 575e7b36-8ec1-46df-b66b-c0228ca93c64), registered 2026-07-02 17:21:00Z, still enabled 14 days later. Never signed in after registration.
Gaps — checks not completed
- Identity Protection riskyUser: 403 (partial Investigator consent). Fix: re-consent
https://login.microsoftonline.com/5c53ae9f-7071-4248-b834-8685b646450f/adminconsent?client_id=bfbc12a4-f0dd-4e12-b06d-997e7271e10c - Consent audit grade AMBER: investigator (missing User.Read.All, Sites.Read.All), exchange-op (missing Mail.ReadWrite, MailboxSettings.ReadWrite), user-manager (missing Directory.ReadWrite.All). Re-consent links in consent-audit output.
Next actions
- [DONE this session] Delete rogue device — see below.
- [DONE this session] Re-revoke sessions.
- Re-consent the three AMBER apps on this tenant (any Global Admin, links above) — ACG.
- Consider phishing-resistant MFA / token-protection CA for this tenant; the "Block Sign-ins Outside US" policy did not stop a US-datacenter AiTM proxy. — ACG, discuss with Mike.
- User awareness: orders@ operator was almost certainly phished ~Jul 2; worth a heads-up to the client contact.
Remediation actions
| Time (UTC) | Action | Tier | Result |
|---|---|---|---|
| 2026-07-16 ~17:0x | DELETE /v1.0/devices/575e7b36-8ec1-46df-b66b-c0228ca93c64 (DESKTOP-YQL6X9KX) |
tenant-admin | HTTP 204; verified — only legit device ORDERSTY remains registered to user |
| 2026-07-16 ~17:0x | POST /v1.0/users/3739c527-f156-49b7-8779-a19033564a0f/revokeSignInSessions |
user-manager | HTTP 200, value=true |
Tenant-wide sign-in sweep for 172.245.92.208 (30d): only the two orders@ events on 2026-07-02. No lateral spread.
Data artifacts
Raw JSON saved at /tmp/remediation-tool/5c53ae9f-7071-4248-b834-8685b646450f/user-breach/Orders_valleywideplastering_com/ — files:
- 00_user.json, 01_inbox_rules_graph.json, 02_mailbox_settings.json, 03a_InboxRule_hidden.json, 03b_MailboxPermission.json, 03c_RecipientPermission.json, 03d_Mailbox.json, 04a_oauth_grants.json, 04b_app_role_assignments.json, 05_auth_methods.json, 06_signins.json, 07_dir_audits.json, 08a_risky_user.json, 08b_risk_detections.json, 09_sent.json, 10_deleted.json