{"id":29349,"date":"2019-09-27T13:04:01","date_gmt":"2019-09-27T13:04:01","guid":{"rendered":"http:\/\/1ccb868f-6e33-45c9-9d18-38aa61e082d3"},"modified":"2019-09-27T13:04:01","modified_gmt":"2019-09-27T13:04:01","slug":"whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/","title":{"rendered":"WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads"},"content":{"rendered":"<p>Researchers have documented the emergence of a downloader that makes use of Microsoft SQL queries to pull and deliver malicious payloads.&nbsp;<\/p>\n<p>In August this year, Proofpoint researchers found the new, staged downloader, <a href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/new-whiteshadow-downloader-uses-microsoft-sql-retrieve-malware\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">known as WhiteShadow<\/a>, which is being used to deliver a variety of malware to vulnerable systems.&nbsp;<\/p>\n<p>The cybersecurity team said in a blog post on Thursday that WhiteShadow appears to be a &#8220;malware delivery service,&#8221; given its presence in campaigns used to spread malware including Remote Access Trojans (RATs) such as Crimson RAT, and Agent Tesla, AZORult, and keyloggers, among others.<\/p>\n<p><strong>See also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/political-targets-at-risk-as-fancy-bear-returns-with-refreshed-backdoor-malware\/\" target=\"_blank\" rel=\"noopener noreferrer\">Political targets at risk as Fancy Bear returns with refreshed backdoor malware<\/a><\/p>\n<p>In a set of phishing email campaigns launched during August, Proofpoint found WhiteShadow lurking in malicious Microsoft Word and Microsoft Excel attachments, pulled into infected systems by way of Visual Basic macros.&nbsp;<\/p>\n<p>If a victim permitted the macros to be enabled, the downloader would set to work by calling and executing SQL queries pulled from Microsoft SQL Server databases controlled &#8212; and rented &#8212; by threat actors.&nbsp;<\/p>\n<p>WhiteShadow uses an SQLOLEDB connector to link to the database remotely and perform queries. Malware is stored as strings which are ASCII-encoded in the database. Once called upon by WhiteShadow, the payload will write to disk as a PKZip archive of a Windows executable.&nbsp;<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>&#8220;The SQLOLEDB connector is an installable database connector from Microsoft but is included by default in many (if not all) installations of Microsoft Office,&#8221; the researchers say. &#8220;Once the connector is installed on the system, it can be used by various parts of the Windows subsystem and by Visual Basic scripts including macros in Microsoft Office documents.&#8221;<\/p>\n<p><strong>CNET:&nbsp;<\/strong><a href=\"https:\/\/www.cnet.com\/news\/hackers-set-up-a-fake-veteran-hiring-website-to-infect-victims-with-malware\/?ftag=CMG-01-10aaa1b\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">Hackers set up a fake veteran-hiring website to infect victims with malware<\/a><\/p>\n<p>The malicious payload is installed based on configuration settings stored in a script within the attachments.&nbsp;<\/p>\n<p>Early campaign indicators revolve around <a href=\"https:\/\/attack.mitre.org\/software\/S0115\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Crimson<\/a>, a malware family that has been connected to attacks against military and government outfits. The malware has information stealing functionality, is able to perform screen captures, list processes, and is able to harvest emails from Outlook.&nbsp;<\/p>\n<p>It is not known if the latest Crimson spread is related to past campaigns.&nbsp;<\/p>\n<p>In addition to Crimson, Proofpoint has also tracked the downloader being used to deliver malware including Nanocore, njRAT, AgentTesla, and Formbook.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/2019\/09\/27\/a47de3d5-c572-4c1e-bbdb-1556064989ee\/e10a015b42da4b93da57fc781c172a2b\/screenshot-2019-09-27-at-10-40-09.png\" class alt=\"screenshot-2019-09-27-at-10-40-09.png\"><\/span><\/p>\n<p>Proofpoint says the Microsoft SQL technique is not unheard of, but it is a rarity in the wild. Currently, campaigns employing this method are small, but that does not mean they will remain so in the future.&nbsp;<\/p>\n<p><strong>TechRepublic:&nbsp;<\/strong><a href=\"https:\/\/www.techrepublic.com\/article\/latest-research-says-organizations-need-to-integrate-security-principles-with-devops\/?ftag=CMG-01-10aaa1b\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">Latest research says organizations need to integrate security principles with DevOps<\/a><\/p>\n<p>In related news this week, Microsoft researchers discovered thousands of Windows PCs that have been infected with a new form of malware. Known as <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-new-nodersok-malware-has-infected-thousands-of-pcs\/\" target=\"_blank\" rel=\"noopener noreferrer\">Nodersok or Divergent<\/a>, the malware is distributed through malvertising and may either use infected hosts into relays for malicious proxies or to perform click-fraud.&nbsp;<\/p>\n<h3>Previous and related coverage<\/h3>\n<hr>\n<p><strong>Have a tip?<\/strong> Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0<\/p>\n<hr>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/whiteshadow-malware-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The downloader has an unusual way of executing next-stage payloads.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":29350,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-29349","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-09-27T13:04:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1982\" \/>\n\t<meta property=\"og:image:height\" content=\"912\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads\",\"datePublished\":\"2019-09-27T13:04:01+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/\"},\"wordCount\":524,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads.png\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/\",\"name\":\"WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads.png\",\"datePublished\":\"2019-09-27T13:04:01+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads.png\",\"width\":1982,\"height\":912},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/","og_locale":"en_US","og_type":"article","og_title":"WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-09-27T13:04:01+00:00","og_image":[{"width":1982,"height":912,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads","datePublished":"2019-09-27T13:04:01+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/"},"wordCount":524,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads.png","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/","url":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/","name":"WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads.png","datePublished":"2019-09-27T13:04:01+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads.png","width":1982,"height":912},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/whiteshadow-downloader-uses-microsoft-sql-queries-to-deliver-malicious-payloads\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"WhiteShadow downloader uses Microsoft SQL queries to deliver malicious payloads"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/29349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=29349"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/29349\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/29350"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=29349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=29349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=29349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}