{"id":1635,"date":"2021-01-19T21:13:55","date_gmt":"2021-01-20T02:13:55","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=1635"},"modified":"2021-01-19T21:13:56","modified_gmt":"2021-01-20T02:13:56","slug":"vollgar-malware-that-is-launched-with-brute-force","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/","title":{"rendered":"Vollgar &#8211; Malware that is launched with brute force"},"content":{"rendered":"\n<p>Since May 2018, a malware botnet call Vollgar has been launching brute force attacks against Microsoft SQL (MSSQL) databases to take over administrator accounts and then install cryptocurrency mining scripts on the underlying operating system.<\/p>\n\n\n\n<p>The researchers named it &#8220;Vollgar&#8221; after the Vollar cryptocurrency that it mines and uses a password brute force attack to breach SQL servers exposed to the Internet and with weak credentials. Attackers have been reported to have successfully infected nearly 2,000-3,000 database servers daily in recent weeks, with potential victims from the healthcare, aviation, and telecommunications, and higher education sectors in China, India, and the United States. , South Korea and Turkey.<\/p>\n\n\n\n<p>Brute force attacks seeking to guess the password of MSSQL servers have sprayed the entire Internet. And it is said that as of May 2018, they have more than 120 IP addresses used to launch attacks, with most of the IP coming from China.<\/p>\n\n\n\n<p>Fortunately for those concerned, Security Officers released a script to allow sysadmins to detect if any of their Windows MS-SQL servers have been compromised by this particular threat.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How the Vollgar malware attack works<\/h2>\n\n\n\n<p>The Vollgar attack begins with brute force login attempts on MS-SQL servers, which, when successful, allow the attacker to execute a series of configuration changes to execute malicious MSSQL commands and download malware binaries in addition to Ensuring that cmd.exe and ftp.exe executables have the necessary execute permissions, the operator behind Vollgar also creates new backdoor on users of MSSQL database.<\/p>\n\n\n\n<p>Vollgar acts as an installer for different types of RAT and a crypto miner based on XMRig that extracts Monero and an alternative currency called VDS or Vollar which, as we have seen in previous posts, can cause problems in our computer equipment.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since May 2018, a malware botnet call Vollgar has been launching brute force attacks against Microsoft SQL (MSSQL) databases to take over administrator accounts and then install cryptocurrency mining scripts on the underlying operating system. The researchers named it &#8220;Vollgar&#8221; after the Vollar cryptocurrency that it mines and uses a password brute force attack to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1636,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,10],"tags":[97,36,35,269],"class_list":["post-1635","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-botnets","category-cybersecurity","tag-botnet","tag-cybersecurity","tag-malware","tag-vollgar"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Vollgar - Malware that is launched with brute force - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Vollgar, a Botnet or Malware that attacks MSSQL databases with brute force, which we will see right now and what causes these....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vollgar - Malware that is launched with brute force - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Vollgar, a Botnet or Malware that attacks MSSQL databases with brute force, which we will see right now and what causes these....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-01-20T02:13:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-01-20T02:13:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/botnetS.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2000\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minuto\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Vollgar &#8211; Malware that is launched with brute force\",\"datePublished\":\"2021-01-20T02:13:55+00:00\",\"dateModified\":\"2021-01-20T02:13:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/\"},\"wordCount\":296,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/botnetS.png\",\"keywords\":[\"Botnet\",\"Cybersecurity\",\"Malware\",\"Vollgar\"],\"articleSection\":[\"Botnets\",\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/\",\"name\":\"Vollgar - Malware that is launched with brute force - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/botnetS.png\",\"datePublished\":\"2021-01-20T02:13:55+00:00\",\"dateModified\":\"2021-01-20T02:13:56+00:00\",\"description\":\"Vollgar, a Botnet or Malware that attacks MSSQL databases with brute force, which we will see right now and what causes these....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/botnetS.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/botnetS.png\",\"width\":2000,\"height\":1000},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vollgar-malware-that-is-launched-with-brute-force\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Vollgar &#8211; Malware that is launched with brute force\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vollgar - Malware that is launched with brute force - Truxgo Server Blog","description":"Vollgar, a Botnet or Malware that attacks MSSQL databases with brute force, which we will see right now and what causes these....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/","og_locale":"es_MX","og_type":"article","og_title":"Vollgar - Malware that is launched with brute force - Truxgo Server Blog","og_description":"Vollgar, a Botnet or Malware that attacks MSSQL databases with brute force, which we will see right now and what causes these....","og_url":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-01-20T02:13:55+00:00","article_modified_time":"2021-01-20T02:13:56+00:00","og_image":[{"width":2000,"height":1000,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/botnetS.png","type":"image\/png"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"1 minuto"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Vollgar &#8211; Malware that is launched with brute force","datePublished":"2021-01-20T02:13:55+00:00","dateModified":"2021-01-20T02:13:56+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/"},"wordCount":296,"commentCount":2,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/botnetS.png","keywords":["Botnet","Cybersecurity","Malware","Vollgar"],"articleSection":["Botnets","Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/","url":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/","name":"Vollgar - Malware that is launched with brute force - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/botnetS.png","datePublished":"2021-01-20T02:13:55+00:00","dateModified":"2021-01-20T02:13:56+00:00","description":"Vollgar, a Botnet or Malware that attacks MSSQL databases with brute force, which we will see right now and what causes these....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/botnetS.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/botnetS.png","width":2000,"height":1000},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/vollgar-malware-that-is-launched-with-brute-force\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Vollgar &#8211; Malware that is launched with brute force"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=1635"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1635\/revisions"}],"predecessor-version":[{"id":1659,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1635\/revisions\/1659"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/1636"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=1635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=1635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=1635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}