Malware Analysis Report for SolarWinds.Orion.Core.BusinessLayer.dll
SolarWinds Orion is a software suite designed to provide “single pane of glass” monitoring of network devices and applications. On December 13 2020, FireEye revealed that SolarWinds Orion was the victim of a supply chain attack and that the SolarWinds signed file SolarWinds.Orion.Core.BusinessLayer.dll contained a backdoor. SolarWinds deployed the back-doored patch to customers beginning in March 2020. FireEye first identified this backdoor and labeled it SUNBURST. The backdoor is composed of roughly 4,000 lines1 of lightly obfuscated .NET within the SolarWinds.Orion.Core.BusinessLayer.OrionImprovementBusinessLayer class of the malicious dll. The backdoor’s capabilities include: the ability to detect and potentially disable antivirus and forensics tools, basic command and control via DNS, and more advanced command and control via HTTP.