HomeSecurityWindows running MS-SQL Servers are under attack by hackers

Windows running MS-SQL Servers are under attack from hackers

Researchers uncovered a massive attack on Windows running MS-SQL Servers by a group of hackers using a wave of a long-term attack campaign called Vollgar.

Microsoft SQL Server is a database management system developed by Microsoft with the three most popular database platforms that are deployed in various organizations worldwide.

This massive long-running attack , observed until 2018 through the honeypot system, has since launched thousands of attacks on many thousands of MS-SQL servers over the past two years.

MS-SQL Servers

Researchers observed that the Vollgar campaign originates from more than 120 IP addresses and most of the visits come from China.

Surprisingly, this Vollgar campaign attacks around 3,000 MS-SQL servers daily and the victims belong to various sectors such as healthcare, aviation, IT and telecommunications, and higher education from India, Ukraine, Turkey , and South Korea.

“Hackers attempt various forms of attack, including password brute force, to compromise victims’ systems, deploy multiple backdoors, and execute numerous malicious modules, such as multifunctional remote access tools (RATs) and crypto stores,” the Guardicore researchers report.

Another interesting fact of this campaign is that 60% of the infected machines remain for a short period of time and 20% of an attack on MS-SQL server remain infected for a long period of a week or more than 2 weeks and 10% of the victims reappear again and again even after the malware by the system administrators.

Genuine campaign for MS‑SQL Server infection bug & Infrastructure

The campaign began with strong brute force to MS-SQL servers, as a result of successful attempts that will allow them to make various configuration changes that create the possibility of executing arbitrary commands.

During the attack, the hackers added a feature that eliminates other entities of the targeted system and ensures their sole presence, occupying the majority of resources such as bandwidth and CPU power.

To prevent failed attempts, the hackers wrote two VB scripts, including an FTP script that can be uploaded via HTTP, and the receivers are executed from a different location each time.

Researchers have gathered a lot of evidence that shows that the CNC central server originates from China and that 10 different backdoors are used to access the system, read files, perform registry modification, and download and execute scripts.

According to the Guardicore report “we found two CNC programs with GUI in Chinese, a tool for modifying file hash values, a portable HTTP file server (HFS), an FTP server Serv-U and a copy of the mstsc.exe client services executable) that were connecting to victims via RDP.”

Embedding multiple RAT modules into an MS-SQL server

There are two initial Droppers (SQLAGENTIDC.exe or SQLAGENTVDC.exe) that were used to eliminate various mining processes (Rnaphin.exe, xmr.exe and winxmr.exe) using taskkill to gain more computational resources by eliminating the competitors.

Later, the loader runs its copy that connects to the C2 server and checks the new process and queries Baidu Maps to obtain the victim's IP and geographic location and to send the collected data.

During the attack, additional payloads are installed on the victim's PC in the form of RAT modules and an XMRig-based cryptominer.

The RAT modules use different ports, including 22251, 9383 and 3213, to connect to the C2 server to eliminate data redundancy.

Thus, the hackers mine both Monero and another currency called VDS, or Vollar, which combines elements of Monero and Ethereum.

Network administrators are advised not to expose MS-SQL database servers to the Internet and to enable logging to monitor and alert on suspicious, unexpected, or repeated connection attempts.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS