Intrusion Context
Last month, Airbus Protect’s CSIRT responded to an intrusion targeting a vulnerable, internet-facing Windows Server. What began as typical automated scanning quickly transitioned into a targeted attack utilising tools such as SQLMap and vulnerability scanners. By leveraging a flurry of SQL injection attacks, the threat actor successfully enabled xp_cmdshell which facilitated remote code execution. Before the host was contained, the adversary made several attempts to deploy a C2 payload in the form of encrypted shellcode.
Note: Based on our analysis, the DLL observed (test.dll and sqlpf.dll) were the same payload and thus will be used interchangeably.









