Share via

Alert on command - unexpected

Duchemin, Dominique 2,011 Reputation points
2020-09-18T02:22:12.847+00:00

Hello,

I am receiving from our security team this alert:

Source IP: 10.16.101.66

Destination IP: 169.254.2.221
Host Name: VIPMEDOLTPDB01.ad
Contact:
Physical Location:

Alert details:
ip_src: 169.254.2.221,
param: wmic /node:10.16.101.66 service where caption like %MSSQLSERVER% get caption /format:csv
filename: WMIC.exe,
alias_host: VIPMEDOLTPDB01.ad

The command appears to be a request to pull a report in csv format on the mentioned node (10.16.101.66). There have been previous alerts indicating that this is legitimate activity. The SOC is escalating to the user/admin of server to verify the legitimacy of this activity and if it is expected so it may be whitelisted/tuned.

Blockquote

What initiate this command? "wmic /node:10.16.101.66 service where caption like %MSSQLSERVER% get caption /format:csv"
Is this command expetected?
What is the results?

10.16.101.66 is the IP address of the cluster node
169.254.2.221 is the IP of the Microsoft Failover Cluster Virtual Adapter

Thanks,
Dom

Windows for business | Windows Server | Storage high availability | Clustering and high availability
0 comments No comments

3 answers

Sort by: Most helpful
  1. Xiaowei He 9,946 Reputation points
    2020-09-18T09:00:44.61+00:00

    Hi,

    Firstly, please run Cluster Validation to check if there's any error in the report.

    Best Regards,
    Anne

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. Duchemin, Dominique 2,011 Reputation points
    2020-09-20T22:51:02.703+00:00

    Hello,

    What is the next step to find out what task/job started the wmic command listed above?

    Microsoft SQL Server Management Studio 14.0.17213.0
    Microsoft Analysis Services Client Tools 14.0.1016.232
    Microsoft Data Access Components (MDAC) 10.0.14393.0
    Microsoft MSXML 3.0 6.0
    Microsoft Internet Explorer 9.11.14393.0
    Microsoft .NET Framework 4.0.30319.42000
    Operating System 6.3.14393

    Thanks,
    Dom

    Was this answer helpful?

    0 comments No comments

  3. Duchemin, Dominique 2,011 Reputation points
    2020-09-20T22:02:09.843+00:00

    Hi,

    No Errors

    Thanks,
    Dom

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.