logo

Attacking MSSQL Servers

ID: 8d2a429c-0052-54b7-85ec-194697c04f11

STIX ID: report--8d2a429c-0052-54b7-85ec-194697c04f11

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-02-21

Date Updated: 2026-04-28

...
...

Huntress observed MSSQL servers being targeted by brute-force and post-compromise activity in which attackers used the MSSQL bcp utility to export files (PowerShell, batch, and EXE) to a public folder. The scripts would create a privileged local user, add it to administrator groups, disable certain credential protections, and attempt to install AnyDesk and a tunneling tool from an attacker-controlled host (2.57.149.x); AV quarantined an EXE and EDR showed bcp.exe usage, but there was no evidence the deployed scripts executed successfully on the monitored endpoints. The report highlights Turkish-language artifacts, reuse of password patterns across incidents, and recommends basic attack-surface reduction and comprehensive monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.