Attacking MSSQL Servers | Huntress
Common Information
Type Value
UUID 8ee49235-93ed-4b8c-b03c-a7a3b13774c1
Fingerprint b908b2fe00d30e0f
Analysis status DONE
Considered CTI value 0
Text language
Published Feb. 8, 2024, midnight
Added to db Aug. 31, 2024, 9:37 a.m.
Last updated Oct. 29, 2024, 8:37 a.m.
Headline Attacking MSSQL Servers
Title Attacking MSSQL Servers | Huntress
Detected Hints/Tags/Attributes 36/2/12
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 318 Huntress Blog https://www.huntress.com/blog/rss.xml 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details File 119
sqlservr.exe
Details File 2
c:\users\public\music\fodsozkgau.txt
Details File 2
user.ps1
Details File 2
user.bat
Details File 2
kur.bat
Details File 1
c:\users\public\music\4.exe
Details File 2
c:\users\public\music\ad.exe
Details File 25
4.exe
Details File 4
bcp.exe
Details IPv4 2
2.57.149.233
Details IPv4 1
2.57.149.230
Details Windows Registry Key 3
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\wdigest