Files
splunk-security_content/docs/_stories/nobelium_group.md
2021-09-23 21:27:17 -04:00

5.6 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
NOBELIUM Group 2020-12-14 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint
Network_Traffic
Web

Try in Splunk Security Cloud{: .btn .btn--success}

Description

Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and management software. It was discovered by FireEye in December 2020. The actors behind this campaign gained access to numerous public and private organizations around the world.

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint, Network_Traffic, Web
  • Last Updated: 2020-12-14
  • Author: Patrick Bareiss, Michael Haag, Splunk
  • ID: 758196b5-2e21-424f-a50c-6e421ce926c2

Narrative

This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) of the NOBELIUM Group. The threat actor behind sunburst compromised the SolarWinds.Orion.Core.BusinessLayer.dll, is a SolarWinds digitally-signed component of the Orion software framework that contains a backdoor that communicates via HTTP to third party servers. The detections in this Analytic Story are focusing on the dll loading events, file create events and network events to detect This malware.

Detections

Name Technique Type
Anomalous usage of 7zip Archive via Utility, Windows Command Shell, Windows Service, Process Injection, File Transfer Protocols, Regsvr32, Mshta, Service Execution, Obfuscated Files or Information, Rundll32, Scheduled Task, Abuse Elevation Control Mechanism, Exploitation for Client Execution, Web Shell, MSBuild, Rename System Utilities, Trusted Developer Utilities Proxy Execution, Web Protocols, Remote System Discovery Anomaly
Detect Outbound SMB Traffic File Transfer Protocols TTP
Detect Prohibited Applications Spawning cmd exe Windows Command Shell, Command and Scripting Interpreter, Exploitation for Privilege Escalation, Rename System Utilities Hunting
Detect Rundll32 Inline HTA Execution Mshta TTP
First Time Seen Running Windows Service Service Execution, Process Injection, Native API, System Services, Services Registry Permissions Weakness, Windows Service Anomaly
Malicious PowerShell Process - Encoded Command Obfuscated Files or Information Hunting
Sc exe Manipulating Windows Services Windows Service TTP
Scheduled Task Deleted Or Created via CMD Scheduled Task TTP
Schtasks scheduling job on remote system Scheduled Task TTP
Sunburst Correlation DLL and Network Event Exploitation for Client Execution TTP
Supernova Webshell Web Shell TTP
TOR Traffic Web Protocols TTP
Windows AdFind Exe Remote System Discovery TTP

Reference

source | version: 2