Attacking MSSQL Servers, Pt. II | Huntress Blog
ID: f6b17735-f9e3-5bf8-8b9c-96c3789a9b3b
STIX ID: report--f6b17735-f9e3-5bf8-8b9c-96c3789a9b3b
Feed Name: Huntress Blog
Threat Score
Huntress investigated automated MSSQL attacks in which threat actors used xp_cmdshell and bcp.exe to extract binaries from a database table into C:\users\public\music, executed batch files that created a persistent admin account and installed AnyDesk, and were stopped prior to a ransomware deployment; the report provides telemetry, IOCs, MITRE ATT&CK mappings, and recommendations for asset inventory and attack-surface reduction.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
