Threat Actors Achieve Persistence After SQL Injection
ID: b6120a2a-24f3-556e-ab45-40348e6f35bb
STIX ID: report--b6120a2a-24f3-556e-ab45-40348e6f35bb
Feed Name: Huntress Blog
Huntress describes a real-world June incident where an attacker exploited an SQL injection vulnerability in an IIS-served page to gain access to an endpoint, used base64 PowerShell to download additional scripts, conducted reconnaissance (tasklist/svc exfiltration), created an administrative account and enabled Remote Desktop Services for persistence, installed BadIIS malicious IIS modules and an XMRig cryptocurrency miner (using nssm to run it as a service), and attempted defense evasion by modifying file attributes and disabling Windows Defender; the report highlights the breadth of modifications attackers may perform post-compromise and provides mitigation recommendations such as asset inventory, attack surface reduction, patching, restricted access, and root-cause investigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
