About this site

Previous work

Projects

   

   

   

   

   

   

   

   

   

   

DNS extraction or circumvention

Retrieved 2021-07-14

  • Zero (Trust Implementation Using WHOIS, IP, and DNS Data)
  • Retrieved 2021-06-01

  • US Seizes Domains Used by SolarWinds Hackers in Cyber Espionage Attacks (News Nation USA)
  • Retrieved 2021-03-05

  • SolarWinds SUNBURST Backdoor DGA and Infected Domain Analysis (Cybersecurity Insiders)
  • Retrieved 2021-02-16

  • SolarWinds Hack and the Case of DNS Security (secblvd)
  • Retrieved 2021-01-20

  • Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop (MS Security)
  • Retrieved 2021-01-17

  • Cyber Threat Intel Analysis and Expansion of SolarWinds Identified IoCs
  • Retrieved 2021-01-11

  • Robust Indicators of Compromise for SUNBURST (NETRESEC Blog)
  • Retrieved 2021-01-07

  • SolarWinds: How a Rare DGA Helped Attacker Communications Fly Under the Radar (Symantec Blogs)
  • Retrieved 2020-12-24

  • SUNBURST Additional Technical Details (fireeye)
  • Retrieved 2020-12-23

  • Five Solution Providers Breached By SolarWinds Hackers: Researchers
  • Retrieved 2020-12-22

  • SolarWinds victims revealed after cracking the Sunburst malware DGA
  • Prevasio: Sunburst Backdoor, Part III: DGA & Security Software
  • Retrieved 2020-12-19

  • Prevasio: Sunburst Backdoor, Part II: DGA & The List of Victims
  • Retrieved 2020-12-18

  • Sunburst's C2 Secrets Reveal Second-Stage SolarWinds Victims (tpost)
  • Sunburst: connecting the dots in the DNS requests (Securelist)
  • Reassembling Victim Domain Fragments from SUNBURST DNS (NETRESEC Blog)
  • Retrieved 2020-12-16

  • GitHub (RedDrip7/SunBurst_DGA_Decode: SunBurst DGA Decode Script)
  • InfoSec Handlers Diary Blog
  • subdomain & #DGA domain names , #SolarWinds, attacked by #UNC2452 @0xrb (Pastebin.com)
  • Microsoft unleashes ‘Death Star’ on SolarWinds hackers in extraordinary response to breach (GeekWire)
  • Trend data on the SolarWinds Orion compromise
  • Retrieved 2020-12-15

  • Microsoft and industry partners seize key domain used in SolarWinds hack (ZDNet)
  • Prevasio: Sunburst Backdoor: A Deeper Look Into The SolarWinds' Supply Chain Malware
  • Retrieved 2020-12-14

  • research/uniq (hostnames.txt at main · bambenek/research · GitHub)