Martin's Blog

Appendix: Timeline, IOCs, and Artifact Map

Reference back matter for the book, consolidated from the technical analysis and public reporting cited throughout the chapters. External network indicators are defanged; file hashes are verbatim. Provenance flags from the chapters apply: compile timestamps are locally verified; day-level 2019 dates are secondary reporting; the valid Authenticode signature is vendor-documented, not verified here.

A. Master timeline

Date Event Evidence / note
~4 Sep 2019 Actor’s first unauthorized access to SolarWinds SolarWinds investigation (reported date; not locally derived)
~12 Sep 2019 Trial (“skeleton”) code injected into Orion builds SolarWinds investigation (reported date)
10 Oct 2019 Build 8890 ships with the benign empty stub compile 2019-10-10 13:26:39 (verified); DLL a25cadd4…
~4 Nov 2019 Trial code removed secondary
20 Feb 2020 SUNSPOT sample likely built PE TimeDateStamp 2020-02-20 11:40:02 UTC (read locally); CrowdStrike describes it as a likely build date; the timestamp does not establish deployment; c45c9bda…
24 Mar 2020 First weaponized SUNBURST build 9083 → shipped as Hotfix 5 (MSP) compile 2020-03-24 08:52:34 (verified); 32519b85…
24 Mar 2020 (parallel) SUPERNOVA sample PE timestamp (different actor) timestamp 09:16:10 (verified); the sample does not establish its placement vector; public reporting associates deployments with Orion exploitation including CVE-2020-10148; c15abaf5…
~26 Mar 2020 Trojanized DLL reaches customers secondary
21 Apr 2020 SUNBURST build 12394 (2020.2 RTM) compiled 019085a7…
11 May 2020 SUNBURST build 12432 (2020.2 HF1) compiled ce77d116…
Apr–Jun 2020 Trojanized updates distributed; SolarWinds estimated fewer than 18,000 customers may have installed affected software public company estimate; observed CDN URLs are download evidence, not an installation count
mid-2020 Selected victims escalated; TEARDROP/RAINDROP drop Cobalt Strike BEACON 1817a5bf…, be9dbbec…
~4 Jun 2020 Actor removes the injector from the build environment secondary
8 Dec 2020 FireEye discloses its own breach (MFA enrollment alert) public reporting
12 Dec 2020 FireEye notifies SolarWinds Not stated
13 Dec 2020 Public disclosure; FireEye SUNBURST report + YARA; CISA ED 21-01 CISA ED 21-01
14 Dec 2020 SolarWinds files SEC Form 8-K Not stated
15 Dec 2020 Killswitch: avsvmcloud[.]com seized, repointed to 20.140.0.1 (a stand-down range) 20.140.0.1 ∈ 20.140.0.0/15 (verified)
5 Jan 2021 US joint statement: “likely Russian in origin” FBI/CISA/ODNI/NSA joint statement
11 Jan 2021 CrowdStrike publishes SUNSPOT analysis (cluster StellarParticle) CrowdStrike analysis
4 Mar 2021 Microsoft details GoldMax / GoldFinder / SIBOT (NOBELIUM) Microsoft analysis; f2a8bdf1…, 7e05ff08…, 94c58c7f…
15 Apr 2021 US formally attributes to Russia’s SVR (APT29); sanctions; 10 diplomats expelled U.S. Treasury announcement
2022 Mandiant merges UNC2452 into APT29 Mandiant assessment
Oct 2023 → Nov 2025 SEC v. SolarWinds & Brown: charged → most claims dismissed (Jul 2024) → dismissed with prejudice, no penalty (20 Nov 2025) Chapter 10

B. SUNBURST DLL hashes (locally verified)

Build SHA-256 MD5 Verdict
2019.4.5200.8890 a25cadd48d70f6ea0c4a241d99c5241269e6faccb4054e62d16784640f8e53bc e18a6a21eb44e77ca8d739a72209c370 benign (trial stub)
2019.4.5200.9083 32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77 b91ce2fa41029f6955bff20079468448 SUNBURST
2020.2.5200.12394 019085a76ba7126fff22770d71bd901c325fc68ac55aa743327984e89f4b0134 2c4a910a1299cdae2a4e55988a2f102e SUNBURST
2020.2.5300.12432 ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6 846e27a652a5e1bfbd0ddd38a16dc865 SUNBURST

C. SUNBURST network / C2 indicators

All stored base64+DEFLATE-obfuscated in the DLL; decoded in Chapter 4.

D. SUNBURST host-based artifacts

E. The 22 nList signalling ranges

The implant’s behaviour is driven by which range the resolved avsvmcloud[.]com IP falls into (escalate / stand-down / reset; see Chapters 4 §4.5 and 5 §5.4):

10.0.0.0/8      172.16.0.0/12    192.168.0.0/16   224.0.0.0/4      (private/multicast)
fc00::          fec0::           ff00::                            (IPv6 ULA/link/multicast)
41.84.159.0/24  74.114.24.0/21   154.118.140.0/24 217.163.7.0/24
20.140.0.0/15   96.31.172.0/24   131.228.12.0/22  144.86.226.0/24
8.18.144.0/23   18.130.0.0/16*   71.152.53.0/24   99.79.0.0/16*
87.238.80.0/21  199.201.117.0/24 184.72.0.0/15*

* marks the three NetBios entries constructed with ext: true in the implant.

The 15 Dec 2020 killswitch repointed avsvmcloud[.]com to 20.140.0.1, inside the stand-down range 20.140.0.0/15. An implant still resolving through this initial DNS path would interpret the answer as its own disable directive; already handed-off hosts required separate remediation (Chapter 8).

F. Companion sample hashes (SHA-256)

Standalone samples examined for this book: second-stage and related tooling, separate from the four installers.

Family Role SHA-256
SUNSPOT build server injector (taskhostsvc.exe) c45c9bda8db1d470f1fd0dcc346dc449839eb5ce9a948c70369230af0b3ef168
TEARDROP CS BEACON loader (NETSETUPSVC.DLL) 1817a5bf9c01035bcf8a975c9f1d94b0ce7f6a200339485d8f93859f8f6d730c
RAINDROP CS BEACON loader (7z.dll) be9dbbec6937dfe0a652c0603d4972ba354e83c06b8397d6555fd1847da36725
GoldFinder Go HTTP path tracer (UPX-packed) f2a8bdf135caca0d7359a7163a4343701a5bdfbc8007e71424649e45901ab7e2
SUPERNOVA .NET webshell (separate actor) c15abaf51e78ca56c0376522d699c978217bf041a3bd3c71d09193efa5717c71
SUNBURST (12432) the 2020.2.5300.12432 DLL ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6
SIBOT VBScript downloader 7e05ff08e32a64da75ec48b5e738181afb3e24a9f1da7f5514c5a11bb067cbfb
GoldMax/SUNSHUTTLE (unpacked) Go HTTPS backdoor 94c58c7fb43153658eaa9409fc78d8741d3c388d3b8d4296361867fe45d5fa45
GoldMax/SUNSHUTTLE (UPX-packed sibling) same code, rotated C2/tokens ec5f07c169267dec875fdd135c1d97186b494a6f1214fb6b40036fd4ce725def
GoldMax config blob config.dat ciphertext specimen bc7a3b3cfae59f1bfbde57154cb1e7deebdcdf6277ac446919df07e3b8a6e4df

G. Second- and later-stage indicators

H. Evidence → section map

Evidence Section
Benign Orion build 8890 and its decompiled empty stub 3
SUNSPOT sample and decompiled build injection logic 3
SUNBURST decompilation, byte-for-byte identical across the three weaponized builds Chapters 3–4, Epilogue
Recovered 188-unique value FNV blocklist 4
Four Orion installers and their CAB manifests 5
Passive DNS captures, C2 IPs, DGA hostnames, and decoded beacon observations 5
TEARDROP and RAINDROP samples and decompilations 6
Public reporting on Golden SAML, victimology, attribution, and policy 2, 6, 8, 10
SUPERNOVA sample and decompiled LogoImageHandler webshell 7
GoldFinder, SIBOT, and GoldMax/SUNSHUTTLE samples and decompilations 9
SolarWinds platform documentation; SUNBURST’s host process gate and privileged primitives 11
Vendor hashes, indicators, and SUNBURST/TEARDROP YARA rules 8, and throughout

↑ Revisiting the SolarWinds Compromise