MSSQL to ScreenConnect | Huntress Blog
ID: 433e5b06-6580-5a54-aafb-e3f35edc7dc9
STIX ID: report--433e5b06-6580-5a54-aafb-e3f35edc7dc9
Feed Name: Huntress Blog
Huntress analysts investigated alerts on Fortinet EMS endpoints where attackers used MSSQL xp_cmdshell and obfuscated commands to attempt downloading and installing a ConnectWise (ScreenConnect) MSI from remote IPs (95.179.241.10 and 185.56.83.82). The activity appears automated across multiple customers, involved msiexec and PowerShell download cradles, and surfaced distinct indicators (IPs and ScreenConnect instance ID f722dcd0838a377e); monitored endpoints showed failed installation attempts and no confirmed persistent compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
