Deep Dive: Squashing an MSSQL Attack
ID: 06433ce8-334f-5d15-aa12-1bed54eb46d5
STIX ID: report--06433ce8-334f-5d15-aa12-1bed54eb46d5
Feed Name: Huntress Blog
This report analyzes a Windows-based breach where attackers brute-forced MSSQL 'sa' credentials, used xp_cmdshell to execute shell commands, disabled antivirus using Image File Execution Options and taskkill, downloaded multiple malware samples via scripted FTP sessions, and created persistent backdoors (registry Run keys and a malicious service). The write-up includes technical details of the intrusion chain, example commands and registry changes, and IOCs including a SHA256 hash and a command-and-control IP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
