# Attacking MSSQL Servers, Pt. II | Huntress

DevFeed: [Attacking MSSQL Servers, Pt. II | Huntress](<https://devfeed.tech/articles/attacking-mssql-servers-pt-ii-huntress-54212.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/attacking-mssql-servers-pt-ii>)

Author: Team Huntress

Published: 2024-02-29T00:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Batch file](<https://devfeed.tech/topics/batch-file.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [batch](<https://devfeed.tech/tags/batch.md>), [edr](<https://devfeed.tech/tags/edr.md>), [incident](<https://devfeed.tech/tags/incident.md>), [mssql](<https://devfeed.tech/tags/mssql.md>), [password](<https://devfeed.tech/tags/password.md>), [ransomware-attacks](<https://devfeed.tech/tags/ransomware-attacks.md>), [servers](<https://devfeed.tech/tags/servers.md>), [soc](<https://devfeed.tech/tags/soc.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

Huntress documents a second incident involving attacks on MSSQL servers. The investigation found xp_cmdshell activity, commands that extracted executable and batch files, creation of an administrative account, changes to local groups, and ransomware-related activity identified through EDR telemetry and Windows Event Logs.

## Source excerpt

The publication of the first blog post led a Huntress SOC analyst to identify and escalate a second, similar incident. A deeper investigation into the activity made it clear that the Huntress SOC had obviated several Trigona ransomware attacks, protecting customers from the impact of a ransomware infection.