Appendix: Timeline, IOCs, and Artifact Map
Reference back matter for the book, consolidated from the technical analysis and public reporting cited throughout the chapters. External network indicators are defanged; file hashes are verbatim. Provenance flags from the chapters apply: compile timestamps are locally verified; day-level 2019 dates are secondary reporting; the valid Authenticode signature is vendor-documented, not verified here.
A. Master timeline
| Date | Event | Evidence / note |
|---|---|---|
| ~4 Sep 2019 | Actor’s first unauthorized access to SolarWinds | SolarWinds investigation (reported date; not locally derived) |
| ~12 Sep 2019 | Trial (“skeleton”) code injected into Orion builds | SolarWinds investigation (reported date) |
| 10 Oct 2019 | Build 8890 ships with the benign empty stub |
compile 2019-10-10 13:26:39 (verified); DLL a25cadd4… |
| ~4 Nov 2019 | Trial code removed | secondary |
| 20 Feb 2020 | SUNSPOT sample likely built | PE TimeDateStamp 2020-02-20 11:40:02 UTC (read locally); CrowdStrike describes it as a likely build date; the timestamp does not establish deployment; c45c9bda… |
| 24 Mar 2020 | First weaponized SUNBURST build 9083 → shipped as Hotfix 5 (MSP) |
compile 2020-03-24 08:52:34 (verified); 32519b85… |
| 24 Mar 2020 | (parallel) SUPERNOVA sample PE timestamp (different actor) | timestamp 09:16:10 (verified); the sample does not establish its placement vector; public reporting associates deployments with Orion exploitation including CVE-2020-10148; c15abaf5… |
| ~26 Mar 2020 | Trojanized DLL reaches customers | secondary |
| 21 Apr 2020 | SUNBURST build 12394 (2020.2 RTM) compiled |
019085a7… |
| 11 May 2020 | SUNBURST build 12432 (2020.2 HF1) compiled |
ce77d116… |
| Apr–Jun 2020 | Trojanized updates distributed; SolarWinds estimated fewer than 18,000 customers may have installed affected software | public company estimate; observed CDN URLs are download evidence, not an installation count |
| mid-2020 | Selected victims escalated; TEARDROP/RAINDROP drop Cobalt Strike BEACON | 1817a5bf…, be9dbbec… |
| ~4 Jun 2020 | Actor removes the injector from the build environment | secondary |
| 8 Dec 2020 | FireEye discloses its own breach (MFA enrollment alert) | public reporting |
| 12 Dec 2020 | FireEye notifies SolarWinds | Not stated |
| 13 Dec 2020 | Public disclosure; FireEye SUNBURST report + YARA; CISA ED 21-01 | CISA ED 21-01 |
| 14 Dec 2020 | SolarWinds files SEC Form 8-K | Not stated |
| 15 Dec 2020 | Killswitch: avsvmcloud[.]com seized, repointed to 20.140.0.1 (a stand-down range) |
20.140.0.1 ∈ 20.140.0.0/15 (verified) |
| 5 Jan 2021 | US joint statement: “likely Russian in origin” | FBI/CISA/ODNI/NSA joint statement |
| 11 Jan 2021 | CrowdStrike publishes SUNSPOT analysis (cluster StellarParticle) | CrowdStrike analysis |
| 4 Mar 2021 | Microsoft details GoldMax / GoldFinder / SIBOT (NOBELIUM) | Microsoft analysis; f2a8bdf1…, 7e05ff08…, 94c58c7f… |
| 15 Apr 2021 | US formally attributes to Russia’s SVR (APT29); sanctions; 10 diplomats expelled | U.S. Treasury announcement |
| 2022 | Mandiant merges UNC2452 into APT29 | Mandiant assessment |
| Oct 2023 → Nov 2025 | SEC v. SolarWinds & Brown: charged → most claims dismissed (Jul 2024) → dismissed with prejudice, no penalty (20 Nov 2025) | Chapter 10 |
B. SUNBURST DLL hashes (locally verified)
| Build | SHA-256 | MD5 | Verdict |
|---|---|---|---|
2019.4.5200.8890 |
a25cadd48d70f6ea0c4a241d99c5241269e6faccb4054e62d16784640f8e53bc |
e18a6a21eb44e77ca8d739a72209c370 |
benign (trial stub) |
2019.4.5200.9083 |
32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77 |
b91ce2fa41029f6955bff20079468448 |
SUNBURST |
2020.2.5200.12394 |
019085a76ba7126fff22770d71bd901c325fc68ac55aa743327984e89f4b0134 |
2c4a910a1299cdae2a4e55988a2f102e |
SUNBURST |
2020.2.5300.12432 |
ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6 |
846e27a652a5e1bfbd0ddd38a16dc865 |
SUNBURST |
C. SUNBURST network / C2 indicators
All stored base64+DEFLATE-obfuscated in the DLL; decoded in Chapter 4.
- C2 base domain:
avsvmcloud[.]com(per-victim subdomains are DGA-generated at runtime, not stored) - C2 subdomain label:
appsync-api→*.appsync-api.<region>.avsvmcloud[.]com - Region labels:
us-east-1,us-east-2,us-west-2,eu-west-1 - Benign cover precheck host:
api.solarwinds[.]com - HTTP URI cover paths:
swip/upd/...,swip/Upload.ashx,swip/Events,pki/crl/{0}{1}{2}.crl,fonts/woff/...woff2 - User-Agent strings:
SolarWindsOrionImprovementClient/<ver>,Microsoft-CryptoAPI/ - DGA substitution alphabets:
ph2eifo3n5utg1j8d94qrvbmk0sal76c,rq3gsalt6u1iyfzop572d49bnx8cvmkewhj - Actor authoritative NS (passive DNS):
ns1.avsvmcloud[.]com→54.164.147.101;ns2.avsvmcloud[.]com→3.101.88.204
D. SUNBURST host-based artifacts
- Single-instance pipe /
appIdGUID:583da945-62af-10e8-4902-a8f205c72b2e - Victim ID source:
HKLM\SOFTWARE\Microsoft\Cryptography→MachineGuid(+ AD domain + first MAC) - Service enumeration / tamper target:
HKLM\SYSTEM\CurrentControlSet\services(Start = 4disables a service) - Persisted state flags (
.configappSettings):ReportWatcherRetry,ReportWatcherPostpone(+ReportStatus.Truncate= self-disabled) - Dropped path reference:
\OrionImprovement\SolarWinds.OrionImprovement.exe - Host process gate:
GetHash("solarwinds.businesslayerhost") == 17291806236368054941 - Name hash function: FNV-1a-64 with final XOR
0x5BAC903BA7D81967 - Domain-skip filters:
(?i)(solarwinds),(?i)…(test)… - Evasion blocklist: 188 unique values across 189 array slots (137 process slots / 136 unique process names, 17 drivers, 22 services, 13 domains), 100% recovered
E. The 22 nList signalling ranges
The implant’s behaviour is driven by which range the resolved avsvmcloud[.]com IP falls into
(escalate / stand-down / reset; see Chapters 4 §4.5 and 5 §5.4):
10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 224.0.0.0/4 (private/multicast)
fc00:: fec0:: ff00:: (IPv6 ULA/link/multicast)
41.84.159.0/24 74.114.24.0/21 154.118.140.0/24 217.163.7.0/24
20.140.0.0/15 96.31.172.0/24 131.228.12.0/22 144.86.226.0/24
8.18.144.0/23 18.130.0.0/16* 71.152.53.0/24 99.79.0.0/16*
87.238.80.0/21 199.201.117.0/24 184.72.0.0/15*
* marks the three NetBios entries constructed with ext: true in the implant.
The 15 Dec 2020 killswitch repointed
avsvmcloud[.]comto20.140.0.1, inside the stand-down range20.140.0.0/15. An implant still resolving through this initial DNS path would interpret the answer as its own disable directive; already handed-off hosts required separate remediation (Chapter 8).
F. Companion sample hashes (SHA-256)
Standalone samples examined for this book: second-stage and related tooling, separate from the four installers.
| Family | Role | SHA-256 |
|---|---|---|
| SUNSPOT | build server injector (taskhostsvc.exe) |
c45c9bda8db1d470f1fd0dcc346dc449839eb5ce9a948c70369230af0b3ef168 |
| TEARDROP | CS BEACON loader (NETSETUPSVC.DLL) |
1817a5bf9c01035bcf8a975c9f1d94b0ce7f6a200339485d8f93859f8f6d730c |
| RAINDROP | CS BEACON loader (7z.dll) |
be9dbbec6937dfe0a652c0603d4972ba354e83c06b8397d6555fd1847da36725 |
| GoldFinder | Go HTTP path tracer (UPX-packed) | f2a8bdf135caca0d7359a7163a4343701a5bdfbc8007e71424649e45901ab7e2 |
| SUPERNOVA | .NET webshell (separate actor) | c15abaf51e78ca56c0376522d699c978217bf041a3bd3c71d09193efa5717c71 |
| SUNBURST (12432) | the 2020.2.5300.12432 DLL |
ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6 |
| SIBOT | VBScript downloader | 7e05ff08e32a64da75ec48b5e738181afb3e24a9f1da7f5514c5a11bb067cbfb |
| GoldMax/SUNSHUTTLE (unpacked) | Go HTTPS backdoor | 94c58c7fb43153658eaa9409fc78d8741d3c388d3b8d4296361867fe45d5fa45 |
| GoldMax/SUNSHUTTLE (UPX-packed sibling) | same code, rotated C2/tokens | ec5f07c169267dec875fdd135c1d97186b494a6f1214fb6b40036fd4ce725def |
| GoldMax config blob | config.dat ciphertext specimen |
bc7a3b3cfae59f1bfbde57154cb1e7deebdcdf6277ac446919df07e3b8a6e4df |
G. Second- and later-stage indicators
- TEARDROP: disguised payload
festive_computer.jpg(vendor sibling:gracious_truth.jpg); maps BEACON in memory viaVirtualProtect(PAGE_EXECUTE_READWRITE). FireEye published theAPT_Dropper_*_TEARDROPYARA rules. - SIBOT: C2
https://thewire.hologic[.]com/includes; dropc:\windows\system32\drivers\netioc.sys; execrundll32 netioc.sys,NdfRunDllDuplicateIPDefendingSystem(WMI); persistenceHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot; UAChromium/78.0.3882.0 Linux. - GoldMax/SUNSHUTTLE: C2
reyweb[.]com(and siblingnikeoutletinc[.]org);config.dat(AES-CFB + base64); IP185.225.69.69; UA Firefox 75 (sibling Firefox 68); command markerubFxROBRwfswVRWNjLC(rotated per build).
H. Evidence → section map
| Evidence | Section |
|---|---|
Benign Orion build 8890 and its decompiled empty stub |
3 |
| SUNSPOT sample and decompiled build injection logic | 3 |
| SUNBURST decompilation, byte-for-byte identical across the three weaponized builds | Chapters 3–4, Epilogue |
| Recovered 188-unique value FNV blocklist | 4 |
| Four Orion installers and their CAB manifests | 5 |
| Passive DNS captures, C2 IPs, DGA hostnames, and decoded beacon observations | 5 |
| TEARDROP and RAINDROP samples and decompilations | 6 |
| Public reporting on Golden SAML, victimology, attribution, and policy | 2, 6, 8, 10 |
SUPERNOVA sample and decompiled LogoImageHandler webshell |
7 |
| GoldFinder, SIBOT, and GoldMax/SUNSHUTTLE samples and decompilations | 9 |
| SolarWinds platform documentation; SUNBURST’s host process gate and privileged primitives | 11 |
| Vendor hashes, indicators, and SUNBURST/TEARDROP YARA rules | 8, and throughout |