There is currently a computer attempting to gain access to your Microsoft
SQL server as sa (System Administrator). It is using a list of passwords
that has been gathered from various sources on the internet. Gaining
access to your SQL server compromises your data and may allow the aggressor
to take control of the machine.
It may be a good time to change your sa password.
Sniffle has made every attempt to respond to the ISP hosting the attacking
computer. The IP address used by sniffle is almost certainly real.
These attacks almost always originate outside the United States. It is
illegal within the US. If it appears that the attack originates in the
US you should contact the proper authorities.
Sniffle creates and uses several files for this type of attack. It creates
several .tmp files which are converted to .txt files after processing.
Sniffle analyzes and creates the exploit reports every hour. Please do
not delete the .tmp files.
The actual data used in the attack is contained in a text file with the
following format.
YYYY-MM-DD HH-MM-SS-ms ???.???.???.???.txt
Example: 2019-10-23 11-34-10-324 192.168.1.122.txt
The file contains:
Date and Time
UTC offset
Source IP address
Client Name
Login
Password
Application Name
Target SQL Server IP Address
If Sniffle cannot find a contact address in the whois information it dumps the
whois data to a file with the following format:
SQL Whois Lookup Fail 192.168.1.122.txt
Sniffle also adds all failed login attempts to a file:
SQL Server Login Errors.txt
Sniffle also adds the attempt to a file containing the country code of the attack.
SQL Attack Country of Origin.txt
You can look up these codes at:
https://www.ripe.net/participate/member-support/list-of-members/list-of-country-codes-and-rirs
Beyond notifying the hosting ISP, there is very little that can be done to stop
this type attack. You could try using Echo and Kill but chances are the attacks
are coming from a constantly changing set of computers worldwide.
Exploit Details
Source IP-145.255.22.121
Originating Country-RU
Email Response To- abuse@ufanet.ru
Data File Name-C:\WINDOWS\Sniffle\Report\SQL 145.255.22.121.tmp
Number of Records-6790
Whois
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf
% Note: this output has been filtered.
% To receive output for a database update, use the “-B” flag.
% Information related to ‘145.255.16.0 – 145.255.23.255’
% Abuse contact for ‘145.255.16.0 – 145.255.23.255’ is ‘abuse@ufanet.ru’
inetnum: 145.255.16.0 – 145.255.23.255
netname: UBN
descr: JSC “Ufanet”
descr: Ufa, Russia
country: RU
admin-c: UN1646-RIPE
tech-c: UN1646-RIPE
status: ASSIGNED PA
mnt-by: UBN-MNT
created: 2012-08-22T08:04:16Z
last-modified: 2018-08-01T07:12:23Z
source: RIPE
role: Ufanet NOC
address: pr. Oktyabrya, 4/3
address: Ufa, Russia
org: ORG-Zs2-RIPE
admin-c: AS39184-RIPE
tech-c: VO1179-RIPE
tech-c: VDN30-RIPE
abuse-mailbox: abuse@ufanet.ru
nic-hdl: UN1646-RIPE
mnt-by: UBN-MNT
created: 2018-06-06T11:54:33Z
last-modified: 2018-12-11T06:50:32Z
source: RIPE # Filtered
% Information related to ‘145.255.22.0/24AS41704’
route: 145.255.22.0/24
descr: JSC “Ufanet”, Ufa, Russia
origin: AS41704
mnt-by: UBN-MNT
created: 2018-08-15T03:30:18Z
last-modified: 2018-08-15T03:30:18Z
source: RIPE
% This query was served by the RIPE Database Query Service version 1.96 (BLAARKOP)