• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

GandCrab Ransomware Infection Made by Scanning MySQL Databases

5623

A Chinese hacking crew is currently targeting Windows servers that are running MySQL databases in order to infect those systems with the GandCrab ransomware.

This way of attack is a relatively new concept as attacking MySQL servers running on Windows systems to infect them with ransomware is something the cybersecurity firms have never witnessed in a long time.

The attacks were spotted in honeypot's logs by Andrew Brandt, Principal Researcher at Sophos. In a blog article for the Sophos website, he detailed the new scanning activity with its payload.

Brandt said hackers would scan for internet-accessible MySQL databases that would accept SQL commands, check if the underlying server would run on Windows, and then use malicious SQL commands to plant a file on the exposed servers, which they'd later execute, infecting the host with the GandCrab ransomware.

These scans turned out to be opportunistic exploitation of misconfigured or passwordless databases for the threat actors.

According to Brandt, the hackers appeared to have been quite prodigious, while not entirely clear if they were successful.

These attacks are tracked back to a remote server, which had an open directory running server software called HFS, which exposed download stats for the attacker's malicious payloads.

Tags:
elijah
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related Tutorials in GandCrab Ransomware Infection Made by Scanning MySQL Databases

Related Tutorials in GandCrab Ransomware Infection Made by Scanning MySQL Databases

How to remove MySQL package completely on Ubuntu 16.04
How to remove MySQL package completely on Ubuntu 16.04
Apr 17, 2017
How To Install Mysql-Workbench On Linux Mint 20.2
How To Install Mysql-Workbench On Linux Mint 20.2
Apr 27, 2022
How to configure MySQL Master-Master replication in CentOS 7
How to configure MySQL Master-Master replication in CentOS 7
Apr 17, 2017
How to install MySQL from source on CentOS 6
How to install MySQL from source on CentOS 6
Nov 23, 2017
How to Install MySQL 8 on Ubuntu 19.04
How to Install MySQL 8 on Ubuntu 19.04
Jun 18, 2019
How to Install PostgreSQL in FreeBSD
How to Install PostgreSQL in FreeBSD
Nov 9, 2016
How to install DataGrip in Ubuntu
How to install DataGrip in Ubuntu
Jul 23, 2016
How To Install XAMPP Stack On Ubuntu 16.04
How To Install XAMPP Stack On Ubuntu 16.04
Jul 18, 2016

Related Forums in GandCrab Ransomware Infection Made by Scanning MySQL Databases

Related Forums in GandCrab Ransomware Infection Made by Scanning MySQL Databases

MySQL
rolando class=
Mysqldump: Couldn't execute 'SHOW VARIABLES LIKE 'gtid\_mode'': Table 'performance_schema.session_variables' doesn't exist (1146)
May 9, 2019
MySQL
isaiah class=
ERROR! MySQL is not running, but lock file (/var/lock/subsys/mysql) exists
Feb 8, 2017
MySQL
liam class=
How to check mysql history in Linux
Aug 28, 2017
CentOS Web Panel
anettejoseph class=
Centos Web Panel : How to find mysql root password
Jan 30, 2018
Database
john class=
Warning: mysqli::__construct(): (HY000/2002): No route to host
May 23, 2017
MySQL
julian class=
ERROR 1881 (HY000) at line 43: Operation not allowed when innodb_forced_recovery > 0
Apr 22, 2017
MySQL
muhammad ahmad class=
ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock'
May 9, 2019
MySQL
gabriel class=
ERROR 1558 (HY000): Column count of mysql.user is wrong. Expected 43, found 42. Created with MySQL 50560, now running 50642
Dec 14, 2018

Related News in GandCrab Ransomware Infection Made by Scanning MySQL Databases

Related News in GandCrab Ransomware Infection Made by Scanning MySQL Databases

CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
Mar 12, 2019
SQL sequel - worm rear its head after a decade
SQL sequel - worm rear its head after a decade
Feb 8, 2017
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Sep 7, 2019
ECh0raix Ransomware Strain QNAP NAS devices
ECh0raix Ransomware Strain QNAP NAS devices
Jul 30, 2019
'The Nasty List' Instagram Phishing Scam Targets Instagram Credentials
'The Nasty List' Instagram Phishing Scam Targets Instagram Credentials
Apr 19, 2019
NIST Develops Guidelines For Dealing With Ransomware Recovery
NIST Develops Guidelines For Dealing With Ransomware Recovery
Sep 8, 2017
‘NamPoHyu Virus’ ransomware target vulnerable Samba servers
‘NamPoHyu Virus’ ransomware target vulnerable Samba servers
Apr 20, 2019
A Sneaky Ransomware That Seems Benificial. But Deceptive.
A Sneaky Ransomware That Seems Benificial. But Deceptive.
Apr 5, 2019
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Jayce ?
What are the types of table used in IPtables

What are the various types of table used in IPtables and how to use that for my server security?

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.