logo

Deep Dive: Squashing an MSSQL Attack

ID: 06433ce8-334f-5d15-aa12-1bed54eb46d5

STIX ID: report--06433ce8-334f-5d15-aa12-1bed54eb46d5

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2017-07-17

Date Updated: 2026-04-28

...
...

This report analyzes a Windows-based breach where attackers brute-forced MSSQL 'sa' credentials, used xp_cmdshell to execute shell commands, disabled antivirus using Image File Execution Options and taskkill, downloaded multiple malware samples via scripted FTP sessions, and created persistent backdoors (registry Run keys and a malicious service). The write-up includes technical details of the intrusion chain, example commands and registry changes, and IOCs including a SHA256 hash and a command-and-control IP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.