> Source: [sk172367](https://support.checkpoint.com/results/sk/sk172367)

# sk172367 - Check Point response to HAFNIUM Attack

| Property | Value |
|----------|-------|
| Solution ID | sk172367 |
| Date Created | 2021-03-04 |
| Last Modified | 2021-04-08 |
| Technical Level | General |
| Products | Security Gateway, Endpoint Security |
| Versions | R82.10, R82, R81.20, Cloud, R82.10, R82, R81.20 |

## Symptoms

- On March 2, 2021, Microsoft shared details on multiple severe vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) targeting Microsoft Exchange Servers. Microsoft reported that those vulnerabilities have been exploited. More information can be found in the following blog by Microsoft - <https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/>.

## Solution

Check Point provides comprehensive security coverage to the vulnerabilities reported by Microsoft with the following Threat Prevention protections:  

### IPS

1. CVE-2021-26855 - [CPAI-2021-0099](https://www.checkpoint.com/defense/advisories/public/2021/CPAI-2021-0099.html)
2. CVE-2021-26857 - [CPAI-2021-0107](https://www.checkpoint.com/defense/advisories/public/2021/CPAI-2021-0107.html)
3. CVE-2021-26858 - [CPAI-2021-0107](https://www.checkpoint.com/defense/advisories/public/2021/CPAI-2021-0107.html)
4. CVE-2021-27065 - [CPAI-2021-0099](https://www.checkpoint.com/defense/advisories/public/2021/CPAI-2021-0099.html)

### Threat Emulation

1. Trojan.WinsCVE-2021-27065.A

### Anti-Virus

1. HAFNIUM.TC. XXX
2. Trojan.Win32.Hafnium.TC.XXX

### **Harmony Endpoint (SandBlast Agent)**

1. Behavioral.Win.SuspExchange.A
2. Behavioral.Win.SuspExchange.B
3. Behavioral.Win.SuspExchange.C
4. Behavioral.Win.SuspExchange.D

### Threat Hunting

Check Point added a set of predefined queries to Harmony Endpoint Threat Hunting. If you find a match for any of these queries, investigate it immediately. This is the list of the queries:

1. HAFNIUM: Web Shell File Hashes
2. HAFNIUM: Abnormal Exchange Server process execution
3. HAFNIUM: Credential Dumping using procdump.exe
4. HAFNIUM: Credential Dumping utilizing a DLL
5. HAFNIUM: Suspicious PowerShell usage
6. HAFNIUM: Suspicious script execution utilizing PowerCat
7. HAFNIUM: Suspicious Exchange PowerShell Snapin load
8. HAFNIUM: Suspicious IPs outbound traffic
9. HAFNIUM: Suspicious IPs inbound traffic
10. HAFNIUM: Creation of suspicious files by the Exchange Server
11. HAFNIUM: Creation of suspicious files by the Exchange Server 2
12. HAFNIUM: Known Web Shell file names
13. HAFNIUM: ASPX Web Shell file based indicator
14. HAFNIUM: ASPX Web Shell file based indicator 2
15. HAFNIUM: Exfiltration file based indicators
16. HAFNIUM: Suspicious AMSI content

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
