Main Menu
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • SonicWall Promotions
    • Competitive Trade-In
    • Secure Upgrade Plus
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
SonicWall
  • Products
    • Network Security
      • Next Generation FirewallNext-generation firewall for SMB, Enterprise, and Government
      • Security ServicesComprehensive security for your network security solution
      • Capture Security applianceAdvanced Threat Protection for modern threat landscape
      • Network Security ManagerModern Security Management for today’s security landscape
    • Access Security
      • Cloud Edge Secure AccessDeploy Zero-Trust Security in minutes
      • Secure Mobile AccessRemote, best-in-class, secure access
      • Wireless Access PointsEasy to manage, fast and secure Wi-FI
      • SwitchesHigh-speed network switching for business connectivity
    • Email Security
      • Email SecurityProtect against today’s advanced email threats
    • Cloud Security
      • Cloud App SecurityVisibility and security for Cloud Apps
      • Cloud Firewall (NSv)Next-generation firewall capabilities in the cloud
    • Endpoint Security
      • Capture ClientStop advanced threats and rollback the damage caused by malware
      • Content Filtering ClientControl access to unwanted and unsecure web content
    • Product Widgets
      • Product Menu Right Image
      • Capture Cloud Platform
        Capture Cloud Platform

        A security ecosystem to harness the power of the cloud

    • Button Widgets
      • Products A-Z
        all products A–Z FREE TRIALS
  • Solutions
    • Industries
      • Distributed Enterprises
      • Retail & Hospitality
      • K-12 Education
      • Higher Education
      • State & Local
      • Federal
      • Healthcare
      • Financial Services
      • Carriers
    • Use Cases
      • Secure SD-Branch
      • Zero Trust Security
      • Secure SD-WAN
      • Office 365 Security
      • SaaS Security
      • Secure WiFi
    • Solutions Widgets
      • Solutions Content Widgets
        Federal

        Protect Federal Agencies and Networks with scalable, purpose-built cybersecurity solutions

      • Solutions Image Widgets
  • Partners
    • SonicWall Partners
      • Partners Overview
      • Authorized Distributors
      • Technology Partners
    • Partner Resources
      • Become a Partner
      • SonicWall University
      • Training & Certification
    • Partner Widgets
      • Custom HTML : Partners Content WIdgets
        Partner Portal

        Access to deal registration, MDF, sales and marketing tools, training and more

      • Partners Image Widgets
  • Support
    • Support
      • Knowledge Base
      • Technical Documentation
      • Community
      • Video Tutorials
      • Product Life Cycle Tables
      • Contact Support
    • Resources
      • Resource Center
      • Free Trials
      • Blog
      • Security Center
      • Security News
      • PSIRT
      • SonicWall University
      • MySonicWall
    • Support Widget
      • Custom HTML : Support Content WIdgets
        Support Portal

        Find answers to your questions by searching across our knowledgebase, community, technical documentation and video tutorials

      • Support Image Widgets
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • SonicWall Promotions
    • Competitive Trade-In
    • Secure Upgrade Plus
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
  • Contact Sales
  • English English English en
  • 简体中文 简体中文 Chinese (Simplified) zh-cn
  • Français Français French fr-fr
  • Deutsch Deutsch German de-de
  • 日本語 日本語 Japanese ja-jp
  • 한국어 한국어 Korean ko-kr
  • Português Português Portuguese (Brazil) pt-br
  • Español Español Spanish es-mx
  • English (UK) English (UK) English (UK) en-gb
  • BLOG
  • CONTACT SALES
  • FREE TRIALS
  • English English English en
  • 简体中文 简体中文 Chinese (Simplified) zh-cn
  • Français Français French fr-fr
  • Deutsch Deutsch German de-de
  • 日本語 日本語 Japanese ja-jp
  • 한국어 한국어 Korean ko-kr
  • Português Português Portuguese (Brazil) pt-br
  • Español Español Spanish es-mx
  • English (UK) English (UK) English (UK) en-gb
SonicWall
  • Products
    • Network Security
      • Next Generation FirewallNext-generation firewall for SMB, Enterprise, and Government
      • Security ServicesComprehensive security for your network security solution
      • Capture Security applianceAdvanced Threat Protection for modern threat landscape
      • Network Security ManagerModern Security Management for today’s security landscape
    • Access Security
      • Cloud Edge Secure AccessDeploy Zero-Trust Security in minutes
      • Secure Mobile AccessRemote, best-in-class, secure access
      • Wireless Access PointsEasy to manage, fast and secure Wi-FI
      • SwitchesHigh-speed network switching for business connectivity
    • Email Security
      • Email SecurityProtect against today’s advanced email threats
    • Cloud Security
      • Cloud App SecurityVisibility and security for Cloud Apps
      • Cloud Firewall (NSv)Next-generation firewall capabilities in the cloud
    • Endpoint Security
      • Capture ClientStop advanced threats and rollback the damage caused by malware
      • Content Filtering ClientControl access to unwanted and unsecure web content
    • Product Widgets
      • Product Menu Right Image
      • Capture Cloud Platform
        Capture Cloud Platform

        A security ecosystem to harness the power of the cloud

    • Button Widgets
      • Products A-Z
        all products A–Z FREE TRIALS
  • Solutions
    • Industries
      • Distributed Enterprises
      • Retail & Hospitality
      • K-12 Education
      • Higher Education
      • State & Local
      • Federal
      • Healthcare
      • Financial Services
      • Carriers
    • Use Cases
      • Secure SD-Branch
      • Zero Trust Security
      • Secure SD-WAN
      • Office 365 Security
      • SaaS Security
      • Secure WiFi
    • Solutions Widgets
      • Solutions Content Widgets
        Federal

        Protect Federal Agencies and Networks with scalable, purpose-built cybersecurity solutions

      • Solutions Image Widgets
  • Partners
    • SonicWall Partners
      • Partners Overview
      • Authorized Distributors
      • Technology Partners
    • Partner Resources
      • Become a Partner
      • SonicWall University
      • Training & Certification
    • Partner Widgets
      • Custom HTML : Partners Content WIdgets
        Partner Portal

        Access to deal registration, MDF, sales and marketing tools, training and more

      • Partners Image Widgets
  • Support
    • Support
      • Knowledge Base
      • Technical Documentation
      • Community
      • Video Tutorials
      • Product Life Cycle Tables
      • Contact Support
    • Resources
      • Resource Center
      • Free Trials
      • Blog
      • Security Center
      • Security News
      • PSIRT
      • SonicWall University
      • MySonicWall
    • Support Widget
      • Custom HTML : Support Content WIdgets
        Support Portal

        Find answers to your questions by searching across our knowledgebase, community, technical documentation and video tutorials

      • Support Image Widgets
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • SonicWall Promotions
    • Competitive Trade-In
    • Secure Upgrade Plus
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
  • Contact Sales
  • Menu

Product Notifications

< Back to Alerts

SolarWinds Orion Vulnerability

01/15/2021

DESCRIPTION:

Updated January 15, 2021

The U.S. Department of Homeland Security (DHS) and the Cybersecurity and Infrastructure Security Agency (CISA) have confirmed that malicious threat actors have been and are actively exploiting vulnerabilities in SolarWinds Orion products, specifically affecting versions 2019.4 through 2020.2 HF1. These malware variants are capable of transferring data, file execution, system profiling, rebooting and more.

Both SolarWinds and the CISA strongly suggest that organizations using SolarWinds Orion verify the version they’re running and upgrade immediately, if required. More information can be found at www.solarwinds.com/securityadvisory.

SonicWall Capture Labs threat researchers have investigated the vulnerability and published multiple signatures in different categories that identify malicious activity against affected SolarWinds Orion versions. These mitigations include application identification signatures that detect if an organization has SolarWinds Orion deployed within its network; malicious domain signatures; malicious IPs; and malware such as Sunburst, Supernova and Teardrop.

These signatures are applied automatically to SonicWall firewalls with active security subscriptions.

Application Signatures that identify SolarWinds Orion applications:

  • 15296: BUSINESS-APPS SolarWinds Orion (API Activity)
  • 2014: BUSINESS-APPS SolarWinds Orion (Update Activity)

IPS Signatures that identify malicious domains:

  • 15292: SolarWinds Supply Chain Malware Activity 1
  • 15293: SolarWinds Supply Chain Malware Activity 2
  • 15294: SolarWinds Supply Chain Malware Activity 3
  • 15295: SolarWinds Supply Chain Malware Activity 4
  • 15298: SolarWinds Supply Chain Malware Activity 5
  • 15299: SolarWinds Supply Chain Malware Activity 6
  • 15300: SolarWinds Supply Chain Malware Activity 7
  • 15301: SolarWinds Supply Chain Malware Activity 8
  • 15302: SolarWinds Supply Chain Malware Activity 9
  • 15303: SolarWinds Supply Chain Malware Activity 10
  • 15308: SolarWinds Supply Chain Malware Activity 11
  • 15309: SolarWinds Supply Chain Malware Activity 12
  • 15310: SolarWinds Supply Chain Malware Activity 13
  • 15311: SolarWinds Supply Chain Malware Activity 14
  • 15312: SolarWinds Supply Chain Malware Activity 15
  • 15313: SolarWinds Supply Chain Malware Activity 16
  • 15314: SolarWinds Supply Chain Malware Activity 17
  • 15315: SolarWinds Supply Chain Malware Activity 18
  • 15316: SolarWinds Supply Chain Malware Activity 19
  • 15317: SolarWinds Supply Chain Malware Activity 20

Gateway antivirus (GAV) signatures that identify malware (Updated January 14):

Sunburst: A backdoor malware that has been trojanized into multiple SolarWinds Orion update versions.

  • SunBurst.A (Trojan) IOC:d0d626deb3f9484e649294a8dfa814c5568f846d5aa02d4cdad5d041a29d5600
  • SolarWinds.DL (Trojan), IOC:ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6
  • SunBurst.A_1 (Trojan), IOC:32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77
  • SunBurst.A_2 (Trojan), IOC:ad2fbf4add71f61173975989d1a18395afb8538ed889012b9d2e21c19e98bbd1

Supernova: A webshell planted in the code of the Orion network and applications monitoring platform and enabled adversaries to run arbitrary code on machines using the trojanized versions of the Orion software.

  • Injector.DN_35 (Trojan) IOC:c15abaf51e78ca56c0376522d699c978217bf041a3bd3c71d09193efa5717c71
  • Supernova.A_1 (Trojan), IOC:1c96021ac8cb52173e762f6b008fb4c6e5ef113e6baa4e2cf4848e88c61d9700

Teardrop: A memory-only dropper that runs as a service.

  • Teardrop.B (Trojan), IOC:6e4050c6a2d2e5e49606d96dd2922da480f2e0c70082cc7e54449a7dc0d20f8d

Blocked Domains (Updated January 15):

  • avsvmcloud.com
  • digitalcollege.org
  • freescanonline.com
  • deftsecurity.com
  • thedoccloud.com
  • virtualdataserver.com
  • incomeupdate.com
  • databasegalore.com
  • panhardware.com

SonicWall products and real-time security services can help organizations identify Sunburst, Supernova and Teardrop malware and other attacks against vulnerable SolarWinds Orion versions.

To verify you have the latest SonicWall Intrusion Prevention Signatures (IPS), please follow the steps in this knowledge base (KB) article: https://www.sonicwall.com/support/knowledge-base/detailed-information-on-intrusion-prevention-signature-ips-signature-ids/170505742887527/

Additional details regarding this vulnerability can be found in this SonicAlert: https://securitynews.sonicwall.com/xmlpost/solarwinds-orion-vulnerability/

Company
  • Careers
  • News
  • Leadership
  • Awards
  • Press Kit
  • Contact Us
Popular resources
  • Communities
  • Blog
  • SonicWall Capture Labs

Stay In Touch

  • By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement. You can unsubscribe at any time at Manage Subscriptions.
  • This field is for validation purposes and should be left unchanged.
  • Facebook
  • Twitter
  • Linkedin
  • Youtube
  • Instagram

© 2021 SonicWall. All Rights Reserved.

  • Legal
  • Privacy
  • English
    • 简体中文 (Chinese (Simplified))
    • Français (French)
    • Deutsch (German)
    • 日本語 (Japanese)
    • 한국어 (Korean)
    • Português (Portuguese (Brazil))
    • Español (Spanish)
    • English (UK) (English (UK))
Scroll to top
Trace:2425f0fb74872068181c49de4a73c132-74