Inthis blog, we will share an overview of its operation and function, tactics and techniques that support the hypothesis of an advanced persistent threat (APT), and what protections that Palo Alto Networks provides against trojanized SolarWinds instances:
Although .NET webshells are fairly common, most publicly researched samples ingest command and control (C2) parameters, and perform some relatively surface-level exploitation. Some examples would be an attacker commanding the implant to dump directory structures or operating system information, or to perform a network call to load more exploitation tools.
SUPERNOVA differs dramatically in that it takes a valid .NET program as a parameter. The .NET class, method, arguments and code data are compiled and executed in-memory. There are no additional forensic artifacts written to disk, unlike low-level webshell stagers, and there is no need for additional network callbacks other than the initial C2 request.
The implant itself is a trojanized copy of app_web_logoimagehandler.ashx.b6031896.dll, which is a proprietary SolarWinds .NET library that exposes an HTTP API. The endpoint serves to respond to queries for a specific .gif image from other components of the Orion software stack. The relatively high quality code that was added to the .dll is innocuous and easily missed by defender automation, and even potentially by manual review.
The attackers have leveraged the benign file by adding four new parameters to the API and a malicious method that executes the parameters in the context of the .NET runtime on the Orion host. Figure 1 below demonstrates the normal or benign content of the Orion component.
Line 42 defines the collection of the parameters supplied to the HTTP endpoint, in which only id is valid and processed. However, the additional C2 parameters are added before this snippet in the same method, ProcessRequest(), and the execution method is appended in this same file. Figure 2 shows part of the malicious code (lines 27-41).
Any ingress traffic to logoimagehandler.ashx with a combination of these four parameters in any order of the query string are strong indicators of compromise (IOCs). If a detection fires on this combination in any order, please isolate and image your Orion instance immediately. If the request came internal to the network, then it is highly probable that the user that initiated the request has also been compromised.
The try/catch block beginning on line 27 that encompases the execution on line 37 has been added to presumably prevent operator error from causing an unhandled exception in Orion, which could trigger unwanted scrutiny. This is one small example of the attention paid by the actors to technical and operational security.
On lines 106 and 107, we can observe the innocuous compiler API flags that are subverted to impede defenders. Line 115 instantiates the class object specified by the attacker, and on line 116 the attacker code is executed.
In many ways, this webshell exhibits attributes common to other types of webshells. The malware is secretly implanted onto a server, it receives C2 signals remotely and executes them in the context of the server user.
However, this is rarely encountered in webshell behavior, as typical webshells execute their payloads either in the context of the runtime environment or by calling a subshell or process (cmd.exe, PowerShell.exe or /bin/bash).
SUPERNOVA compiles the parameters on the fly and executes the resulting assembly in-memory. Aside from evading detections, this indicates that the SolarStorm actors were adept enough to purposely hide their traffic and behavior in plain sight and to avoid leaving trace evidence behind.
Aside from the numerous protections offered across the Palo Alto Networks product suite, Anti-Spyware signature 83225 has been created to detect any residual C2 infrastructure still present in impacted networks.
The strategy of implanting webshells in vulnerable servers is not a new tactic for malicious actors. However, the relative sophistication of the code compared to routine webshell malware is surprising. Furthermore, the furor of the attacks against SolarWinds further amplifies interest in novel techniques such as those used in SUPERNOVA.
Super-Nova is a superhero-themed visual novel set in the fictional city of Nova. The story follows Nick, a college junior who unexpectedly finds himself drawn into a world of superpowered heroes and villains. He has large shoes to fill as he takes over the role of one of the city's most famous superheroes - Templar. After joining a superhero team, the raccoon will be able to choose a mentor to guide him as they tackle all that Nova City has to offer.
The visual novel will branch into three routes based on the choice of mentor: the mysterious fox Mnesis; the cheerful, enthusiastic tiger Superfang; and the prickly, brash Baron-in-Black. Each route will explore a different facet of the story and world as you forge a stronger bond with your chosen superhero and uncover more of what lies beneath their masks.
just wanted to ask, since the dev log hasn't updated since September( also pls don't forget to do that or something it kinda annoys me when vn's don't - pls and thanks :) ) What's the update that came out 11 days ago?
Hey, thanks for the kind words. Super-Nova is definitely not abandoned, I was just going through a bit of a rough patch, but the next update is coming. I can't promise a steadier pace of updates in the future, since I can never really predict how busy I'll be at my dayjob at any given time, but I have hope that we'll be able to have an update every couple months this year. I would like to make substantial progress on Superfang's route in 2024.
Finally managed to take some time to read more of this game and I'm definitely glad that I did so. I really enjoy the writing, characters, art and music. It really helps diving into the world and putting yourself into the characters perspective. Definitely will continue reading more of it as it comes and good luck with developing, thanks for this absolutely awesome game
So I have a little theory regarding Templar's bracelet. Nothing big, but you can see a pattern. It is visually shown and mentioned that the bracelet has obvious celtic figures on it, such as the dara knot(symbol of strength) and the triskel if I remember right. the surname "O'Connor" is of irish origin, and we can see that the bracelet is on Nick right arm. If we go from the fact that the bracelet is of magical origin, which is probably right, my theory is that it is Nuada silver arm, which is the artificial arm that the god Nuada gained after having own cut off. Nuada is an Irish celtic god, and so the bracelet would be what various media refered in video games and books as "Airgeadlmh,"
As a smut writer, I'm normally pretty disappointed to find out when a VN decides against NSFW scenes, but in all honesty, Super Nova's story is MORE than interesting enough to forgo snu-snu :p in fact, I think it'll be better without!
First time trying and in the first few minutes I'm already sad. Cute handsome badger...why...he was so cool. Poor Templar...well here's hoping Superfang can fill this hole. Main character rubs me the wrong way sometimes but still fine
This novel portrays a luminous stellar explosion releasing powerful electromagnetic radiation and high-energy particles into the universe as far as the solar system, eight light-years away. Around the world, the chromosomes in human cells are damaged by high-energy rays. Only children under thirteen can repair the damage, while other age groups have only about a year left to survive. The world becomes strange at this moment.
Supernova Era first version was created in 1991, but the first official release was in 2003. Liu Cixin has repeatedly revised the book and published three different editions, not including unreleased versions. Of all, the 2009 edition is the longest and most complete. Tor Books published the English translation by Joel Martinsen in 2019.[1]
On a seemingly ordinary summer night, a catastrophe brewing for hundreds of millions of years reaches the Earth from deep space. The radiation from the supernova explosion irreversibly irradiates everyone over the age of 13, leaving them with only a few months to live. Children under 13 years old can recover. That means that all humans over thirteen in the world will die, and the Earth will become a world with only children.
It is a society the world has never seen before; adults are supposed to teach their children life skills in the shortest possible time, such as running a country, commanding an army, etc. The adults also leave their children the best gift, the Chinese Quantum, a super quantum computer, which will help the children go through a dark age that follows. In the early days of the supernova era, the world of children becomes the last continuation of the world of adults. After several months of seemingly smooth operation, it finally gets out of control.
When children are tired of the rules and regulations of the adult world, playing seems to be the only theme of the child world. First, they want to build a candy world, where the building shell is edible chocolate; They have created the maximal online games. Because all children are participants, online community organizations are even equipped to compete with the state power; In the end, they found that the most exciting game is war. Out-of-control children in the Antarctic continent started a world war; After that, China and the United States even exchanged their territory.
A Hugo Award-winning editor, Jason Heller, said, "Liu began writing 'Supernova Era' soon after the political uprising in Beijing's Tiananmen Square in 1989. The book is suffused with a sense of calamity, tragedy, and swift social change."[7]
I first heard about the series during a book club meeting. I have always been a fan of superheroes and villains, so discovering Renegades, a book focused solely on heroes and villains and the gray line that separates them, was an almost guarantee that this series would become one of my favorites. And low and behold, I immediately fell in love.
3a8082e126