Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

China Chopper was the web shell most often found in Microsoft’s investigated attacks against on-premises Exchange servers in 2021. Attackers used Exchange vulnerabilities to gain access, then placed a small server-side script on the compromised server. That script provided a way to run commands through web requests—turning an initial exploit into a foothold for reconnaissance, credential theft, mailbox access, and further payloads.

What web shell did attackers use on Exchange?

Microsoft’s 2021 analysis said most of the Exchange attacks it investigated used the China Chopper web shell. In its report on the initial HAFNIUM campaign, Microsoft also said the operators deployed web shells after gaining access. These findings describe the attacks Microsoft investigated; they do not establish that every compromised Exchange server had China Chopper.

A web shell is a small script placed on a web server that accepts attacker-controlled input in a request and can execute commands in the server’s context. China Chopper was not the vulnerability that opened the server. It was a post-exploitation tool: the vulnerabilities provided a route in, and the shell gave attackers a continuing way to interact with the compromised machine.

How did the shell get onto an Exchange server?

The initial 2021 HAFNIUM campaign targeted internet-facing, on-premises Microsoft Exchange servers. Microsoft identified four vulnerabilities in the attack chain. Their roles differed:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Dell PowerEdge T340 Tower Server, Windows 2019 STD OS, Intel Xeon E-2124 Quad-Core 3.3GHz 8MB, 32GB DDR4 RAM, 8TB Storage, RAID, Single PSU (Renewed)
  • 3.5 Inch Hot Plug Hard Drive PowerEdge T340 Tower Server Chassis
  • Microsoft Windows Server 2019 Standard Operating System
  • Processors: Intel Xeon E-2124 Quad-Core 3.3GHz 8MB CPU, Up To 4.3GHz Turbo
  • Memory: 32GB (2 x 16GB) DDR4 PC4-21300 2666MHz Unbuffered Memory
  • Hard Drive: 8TB (4 x 2TB) 7.2K RPM 6Gb/s SATA 3.5 Inch HDDs in RAID
  • CVE-2021-26855: A server-side request forgery (SSRF) vulnerability that could let an attacker send arbitrary HTTP requests and authenticate as the Exchange server.
  • CVE-2021-26857: An insecure-deserialization vulnerability in Unified Messaging that could enable code execution as SYSTEM when the attacker had the necessary administrator permission or another exploit.
  • CVE-2021-26858 and CVE-2021-27065: Post-authentication arbitrary-file-write vulnerabilities, which could let an authenticated attacker write a file to an arbitrary path.

The file-write flaws made it practical to place a script in a web-accessible location. Microsoft identified Exchange’s ClientAccess and FrontEnd directory trees as common places to look:

  • %ProgramFiles%MicrosoftExchange Server<version>ClientAccess
  • %ProgramFiles%MicrosoftExchange Server<version>FrontEnd

Those trees include IIS virtual directories that serve Outlook on the web, the Exchange admin center, and AutoDiscover. Microsoft warned that a new .aspx or .ashx file written there by OWA or ECP is highly suspicious. Attackers sometimes used ordinary-looking filenames to blend in, and Microsoft observed echo, certutil.exe, and powershell.exe being used to write shell content.

Microsoft’s notice said Exchange Online was not affected by these particular on-premises vulnerabilities. That distinction applies to the vulnerabilities in this 2021 campaign; it is not a general statement about the security of every Exchange deployment or later vulnerability.

What could an attacker do through the shell?

The shell turned web access into command execution in the Exchange/IIS environment. Microsoft noted that the relevant application pool could run with very high privileges, allowing activity through the shell to reach beyond mailbox functions. What an attacker could do next depended on the server’s configuration and the access they had gained.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reconnaissance

Microsoft observed commands such as whoami, ping, and net user, along with enumeration of local and domain groups. Attackers also queried Exchange for servers, virtual directories, mailboxes, roles, and permissions. On misconfigured systems, Microsoft saw attackers create privileged accounts.

Credential theft and mailbox access

Observed credential-theft methods included saving the SAM database, using ProcDump to dump LSASS memory, deploying Mimikatz variants, and changing WDigest settings so LSASS retained plaintext passwords in memory. Credentials available on the server could provide a route to other systems, so compromise of Exchange could put service accounts and administrator credentials at risk.

Rank #3
Hewlett Packard Enterprise ProLiant MicroServer Gen11 Tower Server, Intel Pentium Gold G7400 Processor, 16GB Memory, 1TB HDD Storage, External 180W US Power Supply (HPE Smart Choice P74439-005)
  • MODEL P74439-005: Compact and affordable HPE ProLiant MicroServer Gen11 powered by Intel Pentium Gold G7400 3.7GHz processor, ideal for file sharing, NAS, and basic business workloads
  • READY OUT OF THE BOX: Includes 16GB DDR5 UDIMM memory (expandable to 128GB), one 1TB SATA 6G Business Critical HDD, embedded Intel VROC SATA, dedicated iLO-M.2 port kit, 180w external power adapter and 1/1/1 warranty for dependable plug-and-play server operation
  • WHISPER-QUIET & SPACE-SAVING: Ultra-compact mini tower design fits easily in small office spaces; supports wall, flat, or vertical placement for deployment flexibility
  • INTEGRATED REMOTE MANAGEMENT: Comes with HPE iLO 6 and embedded TPM 2.0 for secure, license-free remote server administration through shared port access
  • EXPANDABLE DESIGN: Two PCIe slots (including PCIe 5.0) and four LFF-NHP drive bays provide robust options for storage and component scalability. Features new MR408i-p controller support for enhanced storage performance

In the HAFNIUM campaign, Microsoft also observed Exchange PowerShell snap-ins used to export mailbox data and the offline address book downloaded. The latter can expose organizational and user information.

Follow-on tools and payloads

Microsoft’s HAFNIUM reporting described ProcDump, 7-Zip for compressing stolen data, a Nishang reverse shell, and PowerCat connections to a remote server. In later activity, Microsoft documented other actors and techniques rather than one uniform continuation of the HAFNIUM playbook:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Campaign or activity Microsoft-observed behavior
HAFNIUM, initial 2021 campaign Deployed web shells after exploitation; used tools and methods including LSASS dumping, mailbox export, and remote-shell tooling.
DoejoCrypt Used a Chopper variant to write C:WindowsTempxx.bat, back up registry hives, expose credential material, and stage ransomware.
Pydomer Microsoft reported web shells on around 1,500 systems in this campaign-specific observation in 2021. This is not a total for all Exchange compromises.

Microsoft’s broader 2021 reporting described different actors and post-exploitation methods following the vulnerability disclosure. The fact that campaigns involved Exchange exploitation does not make their operators, tooling, or actions interchangeable.

Rank #4
Dell Optiplex 3050 SFF Desktop Computer PC, Intel Quad Core i5-6500 up to 3.6GHz, 16GB DDR4, 256GB SSD, WiFi, 4K Support, DP, HDMI, Windows 11 Pro 64 Bit (Renewed)
  • This Certified Refurbished product is tested and certified to look and work like new. The refurbishing process includes functionality testing, basic cleaning, inspection, and repackaging. The product ships with all relevant accessories, a minimum 90-day warranty, and may arrive in a generic box. Only select sellers who maintain a high-performance bar may offer Certified Refurbished products on Amazon.com.
  • Dell Optiplex 3050 SFF Desktop computer PC, Intel Quad Core i5-6500 up to 3.6GHz, 16GB DDR4, 256GB SSD
  • Includes: USB Keyboard & Mouse, USB WiFi adapter, Microsoft office 30 days free trail.
  • Port: Front: USB 3.0(2), USB 2.0(2); Rear: DP, HDMI, USB 3.0(2), USB 2.0(2), RJ-45.
  • Support 4K (3840x2160) Dual display, makes it easy to connect two monitors at the same time, and you can expand working Windows, mirror content, or expand a single window across multiple monitors.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can you tell whether an Exchange server was compromised?

No single filename or alert proves compromise, and a clean-looking server does not by itself rule it out. Correlate Exchange logs, file changes, process activity, and other indicators into a timeline. Microsoft’s 2021 guidance highlighted these checks:

  1. Check for suspicious shell files. Review ClientAccess and FrontEnd for newly created or modified .aspx and .ashx files. Investigate files written by OWA or ECP, including files with plausible or common names.
  2. Review HTTP proxy logs for SSRF indicators. Examine %PROGRAMFILES%Microsoft Exchange ServerV15LoggingHttpProxy for requests with empty AuthenticatedUser values paired with AnchorMailbox patterns such as ServerInfo~*/*.
  3. Inspect the OAB generator log. Microsoft said legitimate offline address book downloads should land in the OAB Temp directory. A different local or UNC destination warrants investigation.
  4. Look at process ancestry and child processes. Investigate abnormal activity from IIS worker processes such as w3wp.exe, especially launches of cmd.exe, net.exe, mshta.exe, certutil.exe, or PowerShell.
  5. Correlate with other evidence. Check for unexpected account or permission changes, credential-dumping activity, mailbox exports, and other indicators identified by Microsoft. A filename alone is weak evidence; related log and process events can show how a file arrived and what ran afterward.

Microsoft’s 2021 guidance also pointed administrators to its indicators of compromise, Exchange scanning scripts, Defender detections, and advanced hunting queries as investigation aids. Preserve relevant logs and reconstruct the sequence of events rather than treating removal of a suspected shell as the end of the investigation.

What should you do if you find signs of compromise?

  1. Patch the affected on-premises Exchange server and verify its patch level. Patching closes the relevant vulnerability exposure; it does not establish whether an attacker accessed the server before it was patched.
  2. Investigate the full attack chain. Preserve logs and evidence, determine whether web shells or other payloads were created, and review accounts, permissions, processes, and mailbox activity for follow-on actions.
  3. Assume credentials present on an exposed server may be at risk. As part of incident response, rotate affected service-account, scheduled-task, administrator, and other credentials. Consider whether those credentials could have enabled access beyond Exchange.
  4. Use detection and hunting evidence to guide containment. Microsoft’s IOC feeds, Exchange scanning scripts, Defender detections, and advanced hunting queries can help identify activity, but should be considered alongside local logs and the server’s specific history.

Deleting a suspicious script alone is not a complete response: it does not show whether credentials were taken, mailbox data was accessed, other persistence was installed, or further systems were reached.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
Dell PowerEdge T340 Tower Server, Windows 2019 STD OS, Intel Xeon E-2124 Quad-Core 3.3GHz 8MB, 32GB DDR4 RAM, 8TB Storage, RAID, Single PSU (Renewed)
Dell PowerEdge T340 Tower Server, Windows 2019 STD OS, Intel Xeon E-2124 Quad-Core 3.3GHz 8MB, 32GB DDR4 RAM, 8TB Storage, RAID, Single PSU (Renewed)
3.5 Inch Hot Plug Hard Drive PowerEdge T340 Tower Server Chassis; Microsoft Windows Server 2019 Standard Operating System
$1,989.37
Bestseller No. 4
Dell Optiplex 3050 SFF Desktop Computer PC, Intel Quad Core i5-6500 up to 3.6GHz, 16GB DDR4, 256GB SSD, WiFi, 4K Support, DP, HDMI, Windows 11 Pro 64 Bit (Renewed)
Dell Optiplex 3050 SFF Desktop Computer PC, Intel Quad Core i5-6500 up to 3.6GHz, 16GB DDR4, 256GB SSD, WiFi, 4K Support, DP, HDMI, Windows 11 Pro 64 Bit (Renewed)
Includes: USB Keyboard & Mouse, USB WiFi adapter, Microsoft office 30 days free trail.; Port: Front: USB 3.0(2), USB 2.0(2); Rear: DP, HDMI, USB 3.0(2), USB 2.0(2), RJ-45.
$179.98

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.