Free Republic
Browse · Search
News/Activism
Topics · Post Article

Three excerpts from the article:

Earlier today [12/15/2020], a coalition of tech companies seized and sinkholed avsvmcloud[.]com, transferring the domain into Microsoft's possession.

Currently, the avsvmcloud[.]com domain redirects to an IP address owned by Microsoft, with Microsoft and its partners receiving beacons from all the systems where the trojanized SolarWinds app has been installed.

This technique, known as sinkholing, is allowing Microsoft and its partners to build a list of all infected victims, which the organizations plan to use to notify all affected companies and government agencies.

1 posted on 12/19/2020 10:13:01 AM PST by linMcHlp
[ Post Reply | Private Reply | View Replies ]


To: linMcHlp

Hacker is unknown.

https://www.zdnet.com/article/microsoft-fireeye-confirm-solarwinds-supply-chain-attack/

https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html


2 posted on 12/19/2020 10:14:32 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

Dec. 14, 2020:

“Dark Halo Leverages SolarWinds Compromise to Breach Organizations”

https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/


3 posted on 12/19/2020 10:16:15 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies ]

Did Gina Haspel get shot when they seized the domain?


4 posted on 12/19/2020 10:16:40 AM PST by proust (Justice delayed is injustice.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

Dec. 13, 2020

“Austin-based SolarWinds at center of massive US government hack”

https://www.kxan.com/news/local/austin/austin-based-solarwinds-at-center-of-massive-us-government-hack/


6 posted on 12/19/2020 10:19:53 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

The OP is an excerpt.


8 posted on 12/19/2020 10:23:41 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
Microsoft helps kill spread of the SolarWinds hack ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

10 posted on 12/19/2020 10:27:49 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

Dec. 16, 2020

“SolarWinds Removes Customer List From Site as It Releases Second Hotfix”

https://www.securityweek.com/solarwinds-removes-customer-list-site-it-releases-second-hotfix


11 posted on 12/19/2020 10:28:14 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

Dec. 17, 2020

“FireEye and partners release SolarWinds kill-switch”

https://www.computerweekly.com/news/252493790/FireEye-and-partners-release-SolarWinds-kill-switch


12 posted on 12/19/2020 10:30:55 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

Fox guarding the hen house?


14 posted on 12/19/2020 10:36:36 AM PST by fireman15
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

Dec. 18, 2020

“Microsoft, U.S. Energy Dept. Implicated In SolarWinds Hack”

https://www.oann.com/microsoft-u-s-energy-dept-implicated-in-solarwinds-hack/


15 posted on 12/19/2020 10:37:21 AM PST by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

The sophistication of this hack and the clever ways it used to mask its activities and avoid detection has never been seen before according to FireEye analysts. They were able to inject malware into a digitally signed DLL within the SolarWinds download without triggering any key mismatch alerts. They placed code in memory that used the actual admin credentials to traverse servers, extract and move files, and use the backdoor server HTTP parameters to control the malware code.

Anybody that can do this is an expert at exploiting Microsoft’s core. Could this be an insider hack that is supporting a foreign agency? Maybe this is why IT pros that have to build truly secure systems for the government stick with Linux at least for the trusted infrastructure.


16 posted on 12/19/2020 10:39:35 AM PST by Dave Wright
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

They seized a domain? Wow, they’re really on top of this.


17 posted on 12/19/2020 10:42:22 AM PST by perfect_rovian_storm
[ Post Reply | Private Reply | To 1 | View Replies ]

I would also point out that MS-Windows itself is a virus that is constant contact with its Borg masters.


32 posted on 12/19/2020 12:26:17 PM PST by zeugma (Stop deluding yourself that America is still a free country.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

Microsoft strives to be the sole issuer of malware while making holes for other malware.


34 posted on 12/19/2020 12:44:59 PM PST by familyop
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp
This technique, known as sinkholing, is allowing Microsoft and its partners to build a list of all infected victims, which the organizations plan to use to notify all affected companies and government agencies.

But if I just own a computer, not a company or organization, that may not really help me. It might indirectly help by protecting my ISP.

38 posted on 12/19/2020 4:55:08 PM PST by ding_dong_daddy_from_dumas (Re-imagine the media!)
[ Post Reply | Private Reply | To 1 | View Replies ]

Ping


40 posted on 12/19/2020 7:13:19 PM PST by Bob Ireland (The Democrap Party is the enemy of freedom.They use all the seductions and deceits of the Bolshevics)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: linMcHlp

If a domain is taken over can’t they determine who initiated/created/owned it?


44 posted on 12/20/2020 8:03:33 AM PST by killermosquito (Buffalo, Detroit (and eventually France) is what you get when liberalism runs its course.)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson