A Knowledge Base of Attack Campaigns captured by Guardicore Global Sensor Network
Campaign Information
Name
PLEASE_READ_ME
| |
First seen in Guardicore Centra |
2020-01-24 |
Last seen in Guardicore Centra |
2020-11-22 |
This campaign, unlike many others, is not a cryptomining botnet. Here, the attackers compromise victim machines using MySQL brute force, then attempt to encrypt the database. A ransom note is left inside a table called ‘WARNING’, and says: |
Customized Firewall Rules for Your Attack Surface
Deploy our threat intelligence sensors in your organization’s data center
and get rules tailored to the attacks that have tried to compromise your specific environment.
Indicators of Compromise
Source IPs
Connect-Back Servers
–
Attack Flow
Breached Services |
MYSQL |
Tags |
Create Mysql Table MYSQL 31 Sql Commands Malicious Mysql Command |
Incident Summary
Malicious MySQL commands were executed: ALTER TABLE, CREATE DATABASE and INSERT INTO |
Malicious Mysql Command |
MySQL tables were created: PLEASE_READ_ME_XMG.WARNING |
Create Mysql Table |
Connection was closed due to user inactivity |