2020-12-13 SUNBURST SolarWinds Backdoor samples
2020-12-14 22:47:0 Author: contagiodump.blogspot.com(查看原文) 阅读量:10 收藏

2020-12-13 SUNBURST SolarWinds Backdoor samples

I am sure you all saw the news. 

Links updated: Jan 19, 2023

The Resurgence of Russian Threat Actor, NOBELIUM

Well, here are the Sunburst binaries. 

Here is a Sunburst malware analysis walk-through video by Colin Hardy

Hashes

SolarWinds.Orion.Core.BusinessLayer.dll

 Trojan:MSIL/Solorigate.B!dha

A Variant Of MSIL/SunBurst.A

SolarWinds.Orion.Core.BusinessLayer.dll

32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77

dab758bf98d9b36fa057a66cd0284737abf89857b73ca89280267ee7caf62f3b

eb6fab5a2964c5817fb239a7a5079cabca0a00464fb3e07155f28b0a57a2c0ed

c09040d35630d75dfef0f804f320f8b3d16a481071076918e9b236a321c1ea77

ac1b2b89e60707a20e9eb1ca480bc3410ead40643b386d624c5d21b47c02917c

019085a76ba7126fff22770d71bd901c325fc68ac55aa743327984e89f4b0134

ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6

a25cadd48d70f6ea0c4a241d99c5241269e6faccb4054e62d16784640f8e53bc

d3c6785e18fba3749fb785bc313cf8346182f532c59172b69adfb31b96a5d0af

0f5d7e6dfdd62c83eb096ba193b5ae394001bac036745495674156ead6557589

6e4050c6a2d2e5e49606d96dd2922da480f2e0c70082cc7e54449a7dc0d20f8d

CORE-2019.4.5220.20574-SolarWinds-Core-v2019.4.5220-Hotfix5.msp

d0d626deb3f9484e649294a8dfa814c5568f846d5aa02d4cdad5d041a29d5600

appweblogoimagehandler.ashx.b6031896.dll

c15abaf51e78ca56c0376522d699c978217bf041a3bd3c71d09193efa5717c71

TEARDROP

b820e8a2057112d0ed73bd7995201dbed79a79e13c79d4bdad81a22f12387e07

1817a5bf9c01035bcf8a975c9f1d94b0ce7f6a200339485d8f93859f8f6d730c

RAINDROP

be9dbbec6937dfe0a652c0603d4972ba354e83c06b8397d6555fd1847da36725

This is the compromised installer file ( was still on Solarwinds update downloads  on Dec 14, 2020)

File size 419.76 MB

CoreInstaller.msi

ad2fbf4add71f61173975989d1a18395afb8538ed889012b9d2e21c19e98bbd1

2020-04-21 17:31:02

SolarWinds Orion Core Services 2020.2

{77E2D294-3D5C-4D93-ADF1-884CCEAD93B0}

File Version Information

Date signed 05:32 PM 04/21/2020

Signers

Solarwinds Worldwide, LLC

Symantec Class 3 SHA256 Code Signing CA

VeriSign

VT - 0 (Dec 14, 2020)

If you unzip, check 

SolarWinds.Orion.Core.BusinessLayer.dll under OrionCore


文章来源: https://contagiodump.blogspot.com/2020/12/2020-12-13-sunburst-solarwinds-backdoor.html
如有侵权请联系:admin#unsafe.sh