<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sunburst Report in SmartEvent</title>
    <link>https://community.checkpoint.com/t5/SmartEvent/Sunburst-Report/m-p/106253#M12</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image1.png" style="width: 921px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9933iE6FCED14E92D2551/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image1.png" alt="Image1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;***Last update - 24/12/20 - updated after a threat encountered at &lt;A href="https://community.checkpoint.com/t5/SandBlast-Now/bd-p/sandblast-now" target="_blank" rel="noopener"&gt;CloudGuard NDR&lt;/A&gt;. (Kudus&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1366"&gt;@Nir_Naaman&lt;/a&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In December 2020, a large-scale cyberattack targeting many organizations – predominantly tech companies, mainly in the United States, but not only there – was discovered to have been going on for several months. The attack was of a degree of sophistication that led to a quick consensus of involvement by a foreign government, and was extraordinary in both the amount of care taken in crafting it and the exotic vector of entry; instead of the usual phishing or even exploitation, the attackers carried out an elaborate supply chain attack.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;in this report you will be able to see results related to the attack if you have been affected.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2020-12-23 at 12.24.10.jpeg" style="width: 908px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9899i9F121120E6E62E62/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2020-12-23 at 12.24.10.jpeg" alt="WhatsApp Image 2020-12-23 at 12.24.10.jpeg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2020-12-23 at 12.24.11.jpeg" style="width: 833px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9900i9A3B125E603CB8FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2020-12-23 at 12.24.11.jpeg" alt="WhatsApp Image 2020-12-23 at 12.24.11.jpeg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;More materials:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://research.checkpoint.com/2020/sunburst-teardrop-and-the-netsec-new-normal/" target="_blank" rel="noopener"&gt;https://research.checkpoint.com/2020/sunburst-teardrop-and-the-netsec-new-normal/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://blog.checkpoint.com/2020/12/21/best-practice-identifying-and-mitigating-the-impact-of-sunburst/" target="_blank" rel="noopener"&gt;https://blog.checkpoint.com/2020/12/21/best-practice-identifying-and-mitigating-the-impact-of-sunburst/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://blog.checkpoint.com/2020/12/16/solarwinds-sunburst-attack-what-do-you-need-to-know/" target="_blank" rel="noopener"&gt;https://blog.checkpoint.com/2020/12/16/solarwinds-sunburst-attack-what-do-you-need-to-know/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;How to use the report:&lt;BR /&gt;extract the file Sunburst_attack.cpr file to your desktop&lt;BR /&gt;import the report to SmartView application (SmartConsole or Web)&lt;BR /&gt;go to Report TAB&lt;BR /&gt;double click on the report and define the time of query to start from 1.12.20&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;in parallel, run the following query in your smartlog:&lt;BR /&gt;"solartrackingsystem.net" OR "virtualdataserver.com" OR "avsvmcloud.com" OR "freescanonline.com" OR "databasegalore.com" OR "digitalcollege.org" OR "incomeupdate.com" OR "deftsecurity.com" OR "highdatabase.com" OR "websitetheme.com" OR "thedoccloud.com" OR "panhardware.com" OR "avsvmcloud.com" OR "lcomputers.com" OR "zupertech.com" OR "kubecloud.com" OR "webcodez.com" OR "13.59.205.66" OR "54.193.127.66" OR "54.215.192.52" OR "34.203.203.23" OR "139.99.115.204" OR "5.252.177.25" OR "5.252.177.21" OR "204.188.205.176" OR "51.89.125.18" OR "167.114.213.199" OR "avsvmcloud.com" OR *sunburst* OR *sunburs*&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;when analyzing the logs, understand if the log was created from a research that was conducted by a SOC analyst in your network or the source of the activity is a host/server.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;in case you have a log related to one of the indicators OR the report resolved insights, contact Check Point Incident Response Team.&lt;/P&gt;
&lt;P&gt;emergency-response@checkpoint.com&lt;BR /&gt;+1-866-923-0907&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;for more information on "how to import" the report, use the following documentations:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_LoggingAndMonitoring_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_LoggingAndMonitoring_AdminGuide/188029" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_LoggingAndMonitoring_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_LoggingAndMonitoring_AdminGuide/188029&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117773" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117773&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 29 Nov 2025 10:39:07 GMT</pubDate>
    <dc:creator>Oren_Koren</dc:creator>
    <dc:date>2025-11-29T10:39:07Z</dc:date>
    <item>
      <title>Sunburst Report</title>
      <link>https://community.checkpoint.com/t5/SmartEvent/Sunburst-Report/m-p/106253#M12</link>
      <description>200</description>
      <pubDate>Sat, 29 Nov 2025 10:39:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartEvent/Sunburst-Report/m-p/106253#M12</guid>
      <dc:creator>Oren_Koren</dc:creator>
      <dc:date>2025-11-29T10:39:07Z</dc:date>
    </item>
  </channel>
</rss>

