IP Address: 117.117.96.24Malicious
Browse or download a weekly review of our cyber threat intelligence data and gain more insight to help protect your network
IP Address:
117.117.96.24
Malicious
This IP address attempted an attack on a machine protected by Guardicore Centra
Role |
Attacker, Scanner |
Services Targeted |
MSSQL |
Tags |
MSSQL Null Session Login CMD DNS Query Listening Successful MSSQL Login System File Modification Service Configuration File Operation By CMD Outgoing Connection Create MsSql Procedure Drop MsSql Table MSSQL Brute Force Download and Execute Access Suspicious Domain MSSQL |
Associated Attack Servers |
IP Address |
117.117.96.24 |
|
Domain |
- |
|
ISP |
Beijing Education Information Network |
|
Country |
China |
|
WHOIS |
Created Date |
- |
Updated Date |
- |
|
Organization |
- |
First seen in Guardicore Centra |
2019-10-08 |
Last seen in Guardicore Centra |
2021-01-16 |
What is Guardicore CentraGuardicore Centra is a data center and cloud security solution that protects the organization's core assets, using flexible, quickly deployed and easy to understand micro-segmentation controls. Centra generates in-context security incidents, with details on attacker tools and techniques, that help IR teams prioritize incident investigation and reduce dwell time. Learn More
Process c:\windows\system32\lsass.exe started listening on ports: 49158 |
Listening |
A user logged in using MSSQL with the following credentials: sa / ****** - Authentication policy: White List (Part of a Brute Force Attempt) |
Successful MSSQL Login MSSQL Brute Force |
MSSQL procedures were created: sp_addextendedproc , sp_addlogin and sp_password |
Create MsSql Procedure |
MSSQL tables were dropped: #A1E8A56F and #A3D0EDE1 |
Drop MsSql Table |
Process c:\windows\temp\conhost.exe started listening on ports: 32831 |
Listening |
System file C:\Windows\AppCompat\Programs\Amcache.hve was modified 4 times |
System File Modification |
The file C:\Windows\System\down.exe was downloaded and executed |
Download and Execute |
Process c:\windows\s.exe generated outgoing network traffic to: 185.112.156.92:8092 |
Outgoing Connection |
The file C:\Windows\System\msinfo.exe was downloaded and executed |
Download and Execute |
The file C:\Windows\SysWOW64\wpcap.dll was downloaded and loaded by c:\windows\system\msinfo.exe |
Download and Execute |
The file C:\Windows\SysWOW64\npptools.dll was downloaded and loaded by c:\windows\system\msinfo.exe |
Download and Execute |
Process c:\windows\system32\regsvr32.exe attempted to access suspicious domains: js.1226bye.xyz |
DNS Query Access Suspicious Domain |
Connection was closed due to timeout |
|
IP Address: 117.117.96.24Malicious