Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Microsoft and industry partners seize key domain used in SolarWinds hack
ZDNET ^ | 12/15/2020 | Catalin Cimpanu

Posted on 12/19/2020 10:13:01 AM PST by linMcHlp

UPDATED: The seized domain has been turned into a killswitch to prevent the SolarWinds hackers to escalate infections and make new victims.

Microsoft and a coalition of tech companies have intervened today to seize and sinkhole a domain that played a central role in the SolarWinds hack, ZDNet has learned from sources familiar with the matter.

The domain in question is avsvmcloud[.]com, which served as command and control (C&C) server for malware delivered to around 18,000 SolarWinds customers via a trojanized update for the company's Orion app.

SolarWinds Orion updates versions 2019.4 through 2020.2.1, released between March 2020 and June 2020, contained a strain of malware named SUNBURST (also known as Solorigate).


TOPICS: Crime/Corruption; Government; News/Current Events; Technical
KEYWORDS: 202003; bluescreen; cybersecurity; hack; hacking; joke; orionplatform; seizure; solarwinds; windowspinglist; winvirus10
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-62 next last
Three excerpts from the article:

Earlier today [12/15/2020], a coalition of tech companies seized and sinkholed avsvmcloud[.]com, transferring the domain into Microsoft's possession.

Currently, the avsvmcloud[.]com domain redirects to an IP address owned by Microsoft, with Microsoft and its partners receiving beacons from all the systems where the trojanized SolarWinds app has been installed.

This technique, known as sinkholing, is allowing Microsoft and its partners to build a list of all infected victims, which the organizations plan to use to notify all affected companies and government agencies.

1 posted on 12/19/2020 10:13:01 AM PST by linMcHlp
[ Post Reply | Private Reply | View Replies]

To: linMcHlp

Hacker is unknown.

https://www.zdnet.com/article/microsoft-fireeye-confirm-solarwinds-supply-chain-attack/

https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html


2 posted on 12/19/2020 10:14:32 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

Dec. 14, 2020:

“Dark Halo Leverages SolarWinds Compromise to Breach Organizations”

https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/


3 posted on 12/19/2020 10:16:15 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies]

Did Gina Haspel get shot when they seized the domain?


4 posted on 12/19/2020 10:16:40 AM PST by proust (Justice delayed is injustice.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: proust

I thought there was an international governing body that controlled domain names? How does a private company like Microsoft seize the name?


5 posted on 12/19/2020 10:19:44 AM PST by RBW in PA
[ Post Reply | Private Reply | To 4 | View Replies]

To: linMcHlp

Dec. 13, 2020

“Austin-based SolarWinds at center of massive US government hack”

https://www.kxan.com/news/local/austin/austin-based-solarwinds-at-center-of-massive-us-government-hack/


6 posted on 12/19/2020 10:19:53 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

TRUMP: SolarWinds Breach ‘May Be China,’ MSM Won’t Admit Due To ‘Financial Reasons’; “There could also have been a hit on our ridiculous voting machines during the election”
National File ^ | 12/19/2020 | Andrew White
Posted on 12/19/2020, 10:11:49 AM by SeekAndFind

President Donald Trump suggested on Twitter that China ‘may be’ responsible for the recently announced SolarWinds cyber attack, adding that “Russia, Russia, Russia is the priority chant” when anything happens, because mainstream media outlets have “financial reasons” to not cover China’s potential involvement.

President Trump also said that the cyber attack could have impacted “our ridiculous voting machines” during the 2020 US election, adding that the election was a “corrupted embarrassment for the USA.”

This comes after several days of the mainstream media repeatedly blaming Russia or Russian actors for the devastating attack.

….discussing the possibility that it may be China (it may!). There could also have been a hit on our ridiculous voting machines during the election, which is now obvious that I won big, making it an even more corrupted embarrassment for the USA. @DNI_Ratcliffe @SecPompeo

— Donald J. Trump (@realDonaldTrump) December 19, 2020

https://nationalfile.com/trump-solarwinds-breach-may-be-china-msm-wont-admit-due-to-financial-reasons/


7 posted on 12/19/2020 10:21:11 AM PST by Grampa Dave (If voting could change anything, they would not let us do it...!!! Posted by glasseye, 12/19/2020!! )
[ Post Reply | Private Reply | To 2 | View Replies]

To: linMcHlp

The OP is an excerpt.


8 posted on 12/19/2020 10:23:41 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies]

To: proust

Loretta Fuddy did as well.


9 posted on 12/19/2020 10:24:25 AM PST by EEGator
[ Post Reply | Private Reply | To 4 | View Replies]

To: linMcHlp; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
Microsoft helps kill spread of the SolarWinds hack ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

10 posted on 12/19/2020 10:27:49 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

Dec. 16, 2020

“SolarWinds Removes Customer List From Site as It Releases Second Hotfix”

https://www.securityweek.com/solarwinds-removes-customer-list-site-it-releases-second-hotfix


11 posted on 12/19/2020 10:28:14 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

Dec. 17, 2020

“FireEye and partners release SolarWinds kill-switch”

https://www.computerweekly.com/news/252493790/FireEye-and-partners-release-SolarWinds-kill-switch


12 posted on 12/19/2020 10:30:55 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
Sink-holing the primary C&C domain does two good things: 1) prevent further C&C, and 2) helps identify victims when the infection reaches out for C&C.

But it cannot do anything about the compromises and damage done, and continuing to be done, against existing victims. The malware has been running around in systems for months and has long since set up alternatives to the main C&C servers.

13 posted on 12/19/2020 10:32:12 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 10 | View Replies]

To: linMcHlp

Fox guarding the hen house?


14 posted on 12/19/2020 10:36:36 AM PST by fireman15
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

Dec. 18, 2020

“Microsoft, U.S. Energy Dept. Implicated In SolarWinds Hack”

https://www.oann.com/microsoft-u-s-energy-dept-implicated-in-solarwinds-hack/


15 posted on 12/19/2020 10:37:21 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

The sophistication of this hack and the clever ways it used to mask its activities and avoid detection has never been seen before according to FireEye analysts. They were able to inject malware into a digitally signed DLL within the SolarWinds download without triggering any key mismatch alerts. They placed code in memory that used the actual admin credentials to traverse servers, extract and move files, and use the backdoor server HTTP parameters to control the malware code.

Anybody that can do this is an expert at exploiting Microsoft’s core. Could this be an insider hack that is supporting a foreign agency? Maybe this is why IT pros that have to build truly secure systems for the government stick with Linux at least for the trusted infrastructure.


16 posted on 12/19/2020 10:39:35 AM PST by Dave Wright
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

They seized a domain? Wow, they’re really on top of this.


17 posted on 12/19/2020 10:42:22 AM PST by perfect_rovian_storm
[ Post Reply | Private Reply | To 1 | View Replies]

To: RBW in PA

I thought it was ICANN.


18 posted on 12/19/2020 10:43:52 AM PST by Salamander (There's Nothing For It But To Sit And Wait For The Hard Men To Get Me Out....)
[ Post Reply | Private Reply | To 5 | View Replies]

To: fireman15

The hack not only directly networked to servers over the Internet, the hack also networked - spawned - to other areas throughout an organization affected - thus creating multiples of compromised hosts that might have alternative / backdoor communications over the Internet.

Among the hack objectives, was to locate files and delete the files - by removing the paths to the files on Windows OS systems.

Yet, another hack objective, was to set up Wide Area Botnets.

A security feature of the (SolarWinds) Orion Platform, aboard a customer device, is claimed by SolarWinds (if I have that correct), to have indicated a problem that led to SolarWinds hitting the alarm.


19 posted on 12/19/2020 10:46:31 AM PST by linMcHlp
[ Post Reply | Private Reply | To 14 | View Replies]

To: linMcHlp

What if people like Bill Gates came back from Neverland - helping motha earf - lecturing us on global warming - etc - and actually helped the world with some of the stuff he invented?

Seems like Bill Gates and friends could loan us their best people or form a work group and protect the United States from world class hackers.

Would that be too much to ask?


20 posted on 12/19/2020 10:49:16 AM PST by GOPJ (If China let go a virus that primarily killed gays, would Madison Ave. still up Chinese in TV ads? )
[ Post Reply | Private Reply | To 2 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-62 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson