logo

Attacking MSSQL Servers, Pt. II | Huntress Blog

ID: f6b17735-f9e3-5bf8-8b9c-96c3789a9b3b

STIX ID: report--f6b17735-f9e3-5bf8-8b9c-96c3789a9b3b

Feed Name: Huntress Blog

Threat Score
72/100

Date Published: 2024-02-29

Date Updated: 2026-04-28

...
...

Huntress investigated automated MSSQL attacks in which threat actors used xp_cmdshell and bcp.exe to extract binaries from a database table into C:\users\public\music, executed batch files that created a persistent admin account and installed AnyDesk, and were stopped prior to a ransomware deployment; the report provides telemetry, IOCs, MITRE ATT&CK mappings, and recommendations for asset inventory and attack-surface reduction.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.