SolarWinds Backdoor (Sunburst) Incident Response Content Pack
- December 28, 2020
- 0 replies
- 129 views
Summary
FortiGuard Labs is aware of a new sophisticated supply chain attack on SolarWinds, an IT infrastructure management company based in the United States. This attack has been linked to state-sponsored attackers who were able to upload malicious code laden updates to the SolarWinds Orion platform software to unsuspecting victims. SolarWinds Orion platform allows IT administrators an all in one management solution for SolarWinds products. According to their website, SolarWinds provides IT infrastructure management software solutions for 425 of the top Fortune 500 companies. SolarWinds also has many global customers in multiple verticals outside of the Fortune 500, including government, telecom, education and others. Multiple reports by news media outlets have attributed this attack to the Russian government, specifically, APT29/Cozy Bear. Also, it has been reported by various media outlets that this issue is related to the FireEye penetration tools leak from last week.
What are the Technical Details?
SolarWinds has not provided much in detail, however, FireEye has provided a detailed write-up on the threat actor they refer to as UNC2452 and the malware variant referred to as SUNBURST. Victims were compromised by trojanized versions of a legitimate SolarWinds digitally signed file named:
SolarWinds.Orion.Core.BusinessLayer.dll
The trojanized file is a backdoor. Once on a target machine, it remains dormant for a two-week period and will then retrieve commands that allow it to transfer, execute, perform reconnaissance, reboot, and halt system services. Communication occurs over HTTP to predetermined URI's.
The malware utilizes the Orion Improvement Program protocol to evade detection by piggybacking itself as a legitimate service and storing its results within Orion plugin files to avoid further detection. The threat actors used a limited set of malware to avoid detection and used exfiltrated credentials to login to the network remotely for access. Then once inside, the attackers deployed a customized version of the Cobalt Strike beacon for lateral movement. According to the report, the updates were delivered via a two-month window, from March to May of 2020.
(source of above information and more detailed report here: https://www.fortiguard.com/threat-signal-report/3770/supply-chain-attack-on-solarwinds-orion-platform-affecting-multiple-organizations-worldwide-apt2
FortiSOAR Sunburst Hunt & Response Content Pack:
This ‘Sunburst Hunt & Response’ pack adds-on to the FSR Content pack and helps with the following:
- Pulls latest known Sunburst IOCs from verified threat intel repositories
The playbook pulls the latest released IOCs from verified sources such as repositories setup by FireEye, Sophos etc. and creates de-duplicated indicators in the system. The indicators are tagged as #Sunburst IOCs for easy reference across the system.
- Additional enrichment through threat intelligence services
The IOCs are further enriched for information like WHOIS, Location, related artifacts etc. through sources such as Virus Total, AlienVault, URLScan etc. and the additional intelligence is appended to the indicator record. Apart from the identified IOC in question, querying into multiple threat intelligence services returns the related/linked indicators, allowing the SOC teams to evaluate and block them as well - resulting in a more holistic remediation/containment activity.
- Hunts these IOCs in the environment
The IOCs are searched across the environment by querying the SIEM and EDR. The playbooks aim to provide selection of various commonly used SIEM tools, such as FortiSIEM, Splunk, QRadar and ArcSight and forms the search queries accordingly.
- Creates alerts for the sightings found and notify
Based on the indicator sightings, alerts are created with information such as indicator sighted, asset details etc. for further investigation. SOC teams are notified for the hunt summary and findings.
- Provides an ability to block the IOCs found in the hunt
For the IOCs sighted, the response playbook provides a way to block them on FortiGate firewalls and isolated the devices using the FortiEDR integration. The playbook can be easily extended/modified to use EDR/Firewall products of your own choice.
Playbooks in the content pack:
- Hunt Sunburst IOCs
- Hunt Sunburst Indicators
- Block Sunburst Indicators
Deploying the content pack (v 6.4.3+):
- Download the attached package and unzip it
- In your FortiSOAR product, go to Settings > Application Editor > Configuration Import
- Import the package file using the wizard
- Post successful import, you can find the playbooks in collection named 15 - Hunt - Sunburst
- To execute a playbook "Hunt Sunburst IOCs" goto "Hunts" module and create new Hunt record for Sunburst
Supported Versions:
FortiSOAR 6.4.3+
Playbook Screenshots:
