logo

MSSQL to ScreenConnect | Huntress Blog

ID: 433e5b06-6580-5a54-aafb-e3f35edc7dc9

STIX ID: report--433e5b06-6580-5a54-aafb-e3f35edc7dc9

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2024-04-08

Date Updated: 2026-04-28

...
...

Huntress analysts investigated alerts on Fortinet EMS endpoints where attackers used MSSQL xp_cmdshell and obfuscated commands to attempt downloading and installing a ConnectWise (ScreenConnect) MSI from remote IPs (95.179.241.10 and 185.56.83.82). The activity appears automated across multiple customers, involved msiexec and PowerShell download cradles, and surfaced distinct indicators (IPs and ScreenConnect instance ID f722dcd0838a377e); monitored endpoints showed failed installation attempts and no confirmed persistent compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.