Detect MrbMiner Malware

Install metric...

Metrics install automatically if you have SQL Monitor installed.

If you are using Redgate’s SQL Server monitoring tool, SQL Monitor, you can instantly install and run this metric on your servers.

This metric looks for the presence of the MrbMiner malware by checking for an account in sys.sql_logins.

Additional information: https://www.zdnet.com/article/new-mrbminer-malware-has-infected-thousands-of-mssql-databases/

Metric definition

Name

DetectMrbMinerMalware

Description

This metric looks for the presence of the MrbMiner malware by checking for an account in sys.sql_logins.

The T-SQL query that will collect data

Instances to collect from

select all

Databases to collect from

master

Collection frequency

5 mins

Use collected or calculated values

Leave the Use a calculated rate of change between collections check box unchecked

Metric collection

Enabled

Alert definition

Alert name

MrbMiner Malware Detected

Description

An account has been detected that is associated with the MrbMiner malware.

Raise an alert when the metric value goes

above the defined threshholds

Default threshold values

High:0
Medium:
Low:

Raise an alert when the threshold is passed for

collections

Alert is

Enabled