Share via

HAFNIUM Attack

Chris 656 Reputation points
2021-03-06T09:22:14.157+00:00

hello all,
i found in HttpProxy ECP logfiles this entrys . Is this a hafnium attack?

myip /ecp/program.js FBA false ServerInfo~a]@myservername:444/autodiscover/autodiscover.xml?# ExchangeServicesClient/0.0.0.0 211.200.57.186
myip /ecp/program.js FBA false ServerInfo~a]@myservername:444/autodiscover/autodiscover.xml?# ExchangeServicesClient/0.0.0.0 110.10.238.99

Exchange Online
Exchange Online

A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.

0 comments No comments

Answer accepted by question author

Andy David - MVP 160.3K Reputation points MVP Volunteer Moderator
2021-03-06T12:06:22.677+00:00

Run this script to see:

https://github.com/microsoft/CSS-Exchange/tree/main/Security

Download Test-ProxyLogon.ps1

Was this answer helpful?


2 additional answers

Sort by: Most helpful
  1. Andy David - MVP 160.3K Reputation points MVP Volunteer Moderator
    2021-03-08T13:30:24.707+00:00

    Was this answer helpful?

    0 comments No comments

  2. Kai Yao 37,791 Reputation points Moderator
    2021-03-08T02:50:08.037+00:00

    Hi,@Chris

    Please always ensure that you are running the latest version of the script as the script is being updated frequently to ensure there are no false positives.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.