Additional Analysis into the SUNBURST Backdoor
ID: 051d794e-b010-5ff9-abe0-41bae6d2f3f8
STIX ID: report--051d794e-b010-5ff9-abe0-41bae6d2f3f8
Feed Name: McAfee Labs Blog
Executive summary: This McAfee ATR analysis examines the SUNBURST backdoor embedded in SolarWinds.Orion.Core.BusinessLayer.dll, describing how it establishes persistence and stealth via long dormancy, a hardcoded named pipe, system fingerprinting (MD5 UID), service/registry manipulation, extensive system and network reconnaissance, proxy credential harvesting, and DGA-based C2 communications (subdomains of avsvmcloud.com with listed examples and CNAMEs); it highlights indicators and urges further remediation to detect any additional persistence mechanisms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
