{
  "Event": {
    "analysis": "1",
    "date": "2026-07-13",
    "extends_uuid": "",
    "info": "[Threat Intel] Threat Actors Achieve Persistence After SQL Injection",
    "protected": false,
    "publish_timestamp": "1784437661",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1784437661",
    "uuid": "4aaa4284-fee7-4edb-a000-6bceae5f311c",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#8f20d0",
        "local": false,
        "name": "misp-galaxy:producer=\"Huntress\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:sector=\"Technology\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#120044",
        "local": false,
        "name": "rectifyq:sub-category=\"intrusion-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#d92121",
        "local": false,
        "name": "rectifyq:target=\"targeted\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"xmrig\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783998007",
        "to_ids": false,
        "type": "link",
        "uuid": "69a96e66-616f-4c1f-8603-4420c101cc66",
        "value": "https://www.huntress.com/blog/sql-injection-attacker-persistence"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783998007",
        "to_ids": false,
        "type": "text",
        "uuid": "1abd0a7f-b7c3-48fa-9baf-61d32b169186",
        "value": "Threat actors gaining initial access through SQL injection exploited a web application vulnerability in a technology sector organization. After compromising an MSSQL instance via inadequate input validation, the attackers deployed base64-encoded PowerShell scripts to conduct reconnaissance using tasklist commands and exfiltrated results to an external server. They established persistence by enabling Remote Desktop Services, creating an administratively privileged user account named adminweb2$, and disabling Windows Defender. The attackers installed BadIIS modules for SEO fraud, deployed XMRig cryptocurrency miner with hidden file attributes, and utilized service creation tools. Multiple PowerShell scripts and batch files were downloaded throughout the attack to facilitate various malicious operations and maintain access."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783998007",
        "to_ids": false,
        "type": "text",
        "uuid": "862e5368-dba3-4fa9-8d00-e8e349208b88",
        "value": "Name: Threat Actors Achieve Persistence After SQL Injection\nAuthor: AlienVault\nAdversary: \nTags: [\"xmrig\", \"xmrig cryptocurrency miner\", \"badiis modules\", \"remote desktop services\", \"badiis\", \"sql injection\", \"defense evasion\", \"cncrypt protect\", \"iis exploitation\", \"persistence techniques\", \"powershell scripts\"]\nTgtd countries: []\nMlwr families: [\"BadIIS\", \"XMRig\", \"CnCrypt Protect\"]\nAttack_ids: []\nIndustries: [\"Technology\"]"
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 19/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784434426",
        "to_ids": true,
        "type": "md5",
        "uuid": "7564ba00-5bfd-4674-acbf-b5fb1b13a740",
        "value": "c4c8e8c336c3429d97195076bf3bb6eb",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784434711",
        "to_ids": true,
        "type": "hostname",
        "uuid": "97304e50-e7be-4954-93e2-aa714e3f05f4",
        "value": "334thribetlhkyo977gqrcht1k7bvdj2.oastify.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784434733",
        "to_ids": true,
        "type": "hostname",
        "uuid": "ae046496-5823-4eea-b26f-890c400e417f",
        "value": "pub-c4c8e8c336c3429d97195076bf3bb6eb.r2.dev",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784434753",
        "to_ids": true,
        "type": "url",
        "uuid": "3eb1e9fa-2a82-41ee-b987-9bbccac7c2fb",
        "value": "http://334thribetlhkyo977gqrcht1k7bvdj2.oastify.com",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}