[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/detecting-malicious-subdomains/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/detecting-malicious-subdomains/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [DNS](https://unit42.paloaltonetworks.com/category/dns/ "DNS")  
  [DNS](https://unit42.paloaltonetworks.com/category/dns/)

# Subdomain Reputation: Detecting Malicious Subdomains of Public Apex Domains

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Rebekah Houser](https://unit42.paloaltonetworks.com/author/rebekah-houser/)
  * [Daiping Liu](https://unit42.paloaltonetworks.com/author/daiping-liu/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:March 2, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [DNS](https://unit42.paloaltonetworks.com/category/dns/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [C2](https://unit42.paloaltonetworks.com/tag/c2/)
  * [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/)
  * [Web hosting](https://unit42.paloaltonetworks.com/tag/web-hosting/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/detecting-malicious-subdomains/?pdf=download&lg=en&_wpnonce=279fa6c5e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/detecting-malicious-subdomains/?pdf=print&lg=en&_wpnonce=279fa6c5e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Subdomain%20Reputation:%20Detecting%20Malicious%20Subdomains%20of%20Public%20Apex%20Domains&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fdetecting-malicious-subdomains%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdetecting-malicious-subdomains%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdetecting-malicious-subdomains%2F&title=Subdomain%20Reputation:%20Detecting%20Malicious%20Subdomains%20of%20Public%20Apex%20Domains "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdetecting-malicious-subdomains%2F&text=Subdomain%20Reputation:%20Detecting%20Malicious%20Subdomains%20of%20Public%20Apex%20Domains "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdetecting-malicious-subdomains%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Subdomain%20Reputation:%20Detecting%20Malicious%20Subdomains%20of%20Public%20Apex%20Domains%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fdetecting-malicious-subdomains%2F "Share in Mastodon")

## Executive Summary

Cybercriminals regularly leverage popular dynamic domain name system (DDNS) or web hosting services to store and distribute their content. Threat actors leverage these for command and control (C2), malware distribution and phishing. This abuse has created the need for new detection methods for malicious subdomains.

DDNS and web hosting services often allow people to serve content from subdomains of a domain registered by the service provider. These subdomains offer the possibility of detecting malicious activity at the level of the DNS, but to do so is more difficult than detecting malicious registered domains.

Malicious domain detection has typically relied on information that may not be available for these subdomains of registered domains. For example, [WHOIS](https://en.wikipedia.org/wiki/WHOIS) information can reveal whether a domain has recently been registered, and (in some cases) who registered the domain. WHOIS information is not available for the subdomains of public apex domains, though.

Given this lack of information typically used to detect malicious domains, identifying malicious subdomains requires new methods. Palo Alto Networks has developed a system to detect malicious subdomains of public apex domains.

The detections generated by this detector are available to [Palo Alto Networks Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) customers with [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions), including [DNS Security](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/dns-security) and [Advanced URL Filtering](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/url-filtering-features/advanced-url-filtering.html).

| **Related Unit 42 Topics** | [**DNS**](https://unit42.paloaltonetworks.com/tag/dns/) |
|----------------------------|---------------------------------------------------------|

## The DNS and Delegation

The DNS serves as the directory of the internet: a globally distributed database containing information about all the domain names that exist within the internet. To store and retrieve information for the vast number of domains in use, the DNS depends on delegation.

Various groups -- including companies, governments and educational institutions -- are responsible for managing portions of the DNS namespace. These groups control what domains are registered within the portion of the namespace they manage. They also maintain records for these domains and run servers that distribute those records.

For example, Verisign manages the .com top level domain (TLD). Verisign works with registrars to allow people to register names in the .com TLD, such as paloaltonetworks\[.\]com. It also maintains nameservers that refer people to where they can find information about these domains.

Similarly, Palo Alto Networks manages paloaltonetworks\[.\]com. We create subdomains, such as www\[.\]paloaltonetworks\[.\]com, and ensure DNS records for those subdomains are available in authoritative nameservers.

Delegation of responsibility for a domain usually happens when a domain is registered. Top level domains (TLDs) such as .com or .edu are, of course, special cases. The Internet Assigned Numbers Authority (IANA) delegates authority for TLDs through processes unique to TLDs. At lower levels of the DNS namespace, where most of the delegating action occurs, responsibility for a domain belongs to the party that registers the domain.

Typically only the party that registers a domain uses that domain (known as the apex domain) and its subdomains to provide content or services. For example, only Palo Alto Networks uses paloaltonetworks\[.\]com and its subdomains. For some registered domains, however, many parties may control subdomains. We refer to these domains as public apex domains. Figure 1 illustrates the two scenarios.

The case in which multiple parties control subdomains of a registered domain frequently occurs when the domain registrant runs a service that allows people to claim subdomains of its registered domain. Dynamic DNS providers and web hosting platforms frequently provide this option.
![Image 1 is a diagram of the use of registered domains including top level domains (TLDs). From the root, a .com TLD can be either the apps page of Palo Alto Networks or the main Palo Alto Networks site. Other registered domains include duckpins.org sites.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-1.png) Figure 1. Scenarios for use of registered domains.

While the providers can -- and often do -- remove malicious domains and content, they are not creating the content or services represented by these subdomains. This arrangement creates challenges for detecting malicious subdomains.

## Malicious Domain Detection

Malicious domain detection relies on various sources of information. First, we can observe attacks and blocklist the domains involved. This is a standard and helpful approach, but it only covers a portion of the threats evident in the DNS. Also, as a reactive measure, it may detect malicious domains too late to stop many attacks.

Other approaches look at the characteristics of observed domain names or their subdomains to determine if they are likely to have been generated by a domain generation algorithm ([DGA](https://unit42.paloaltonetworks.com/threat-brief-understanding-domain-generation-algorithms-dga/)), or used for [DNS Tunneling](https://unit42.paloaltonetworks.com/dns-tunneling-how-dns-can-be-abused-by-malicious-actors/). Still more can be learned from assessing a domain's reputation.

Reputation comprises information about a domain such as age, usage patterns, popularity, what IP addresses it uses and what other domains use the same IP addresses. [Newly registered domains](https://unit42.paloaltonetworks.com/newly-registered-domains-malicious-abuse-by-bad-actors/) or domains that have been dormant since registration ([strategically aged domains](https://unit42.paloaltonetworks.com/strategically-aged-domain-detection/)) are treated with caution.

If a domain resolves to IP addresses in diverse networks over a short period, it is likely to be a [fast-flux domain](https://unit42.paloaltonetworks.com/fast-flux-101/). These are just some of the ways in which a domain's characteristics build its reputation and suggest whether it's malicious. For subdomains of public apex domains, though, much of this information is not available or not helpful.

## Malicious Subdomains: A New Challenge

DDNS is a technology that allows domains to map to different IP addresses over time without requiring network operators to manually change DNS records. Some providers of DDNS services allow people to manage subdomains of the provider's registered domains.

For example, No-IP offers people the ability to create subdomains under 80 of its registered domains, including ddns\[.\]net and couchpotatofries\[.\]org. Similarly, FreeDNS enables users to claim subdomains of several thousand domains such as chickenkiller\[.\]com and undo\[.\]it. These free subdomains allow users who do not want to go to the expense or trouble of registering a domain to use the DNS for locating their servers.

Other services easing entry into the internet include various hosting platforms. Many well-known companies offer tools and resources that allow users to easily create and distribute content.

These providers may also offer people free subdomains from which to serve their content. For example, bloggers can share stories from subdomains of blogspot\[.\]com, researchers can showcase their projects at subdomains of github\[.\]io and companies building websites with Netlify can host those sites from subdomains of netlify\[.\]app.

Some providers of public apex domains have a large number of users and thus they have a non-trivial impact on the shape of DNS traffic. For example, in a day's worth of Palo Alto Networks passive DNS data, the records for 93% of the top-level domains contained fewer than 87,000 unique registered domains. This is fewer than the number of subdomains seen for public apex domains such as github\[.\]io, netlify\[.\]app or ddns\[.\]net.

In the same passive DNS dataset, the number of subdomains for netlify\[.\]app was greater than the number of registered domains for the .tokyo and .work TLDs, both of which are in the [top 10 TLDs for grayware](https://unit42.paloaltonetworks.com/top-level-domains-cybercrime/) use. Of course, these public apex domains only account for a tiny portion of the DNS traffic seen. Nonetheless, the fact that they have more subdomains than many TLDs demands that we consider their unique dynamics and how well we can characterize their subdomains.

This consideration becomes more pressing given attackers' proclivity to use subdomains of public apex domains in their campaigns. Attackers regularly leverage DDNS to manage their infrastructure. Examples of this include [C2 servers for Adwind malware](https://unit42.paloaltonetworks.com/unit42-exploring-cybercrime-underground-part-3-rat-nest/) and hosts used for [COVID-19 related phishing campaigns](https://unit42.paloaltonetworks.com/silverterrier-covid-19-themed-business-email-compromise/).

Other malicious campaigns have incorporated various hosting services. For example, the [Aggah campaign used Blogger](https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/) to serve malicious scripts, and attackers have hosted [various phishing campaigns on GitHub Pages](https://www.proofpoint.com/us/threat-insight/post/threat-actors-abuse-github-service-host-variety-phishing-kits).

Detecting which subdomains of public apex domains are malicious presents several unique challenges, as traditional approaches might not work or could require adjustments. Domain name characteristics are still somewhat helpful. For example, a random domain name like yjhtbgvfdcsdx\[.\]duckdns\[.\]org or a group of very similar domain names (e.g., nicetshirt171\[.\]blogspot\[.\]com, nicetshirt180\[.\]blogspot\[.\]com, nicetshirt186\[.\]blogspot\[.\]com) are inherently suspicious.

However, there are complications to using these characteristics for detection. Some providers might offer default algorithmically generated subdomain names that are DGA-like or very similar to each other. These characteristics would trigger many false positives if we used typical DGA detection approaches.

Establishing subdomain reputation is also more difficult than with registered domains. Information from WHOIS data does not help, as that pertains to the apex domain, not the subdomain itself.

Similarly, information about nameservers or sibling domains is not helpful, as the service provider manages the nameserver, and sibling domains are owned by thousands of different users. IP reputation might still help with DDNS domains, but for subdomains belonging to hosting providers, IP address information is practically useless. These subdomains resolve to the providers' IP addresses which, like the nameservers, are shared by thousands of subdomains controlled by unrelated parties.

In short, traditional approaches to building domain reputation are insufficient to characterize subdomains of public apex domains. We need new approaches, and that is what Palo Alto Networks has developed.

## Detecting Malicious Subdomains of Public Apex Domains

The system Palo Alto Networks has developed for detecting malicious subdomains of public apex domains uses the same basic principles as traditional malicious domain detection approaches. They check for suspicious lexical characteristics, and evaluate reputation. However, the methods for determining what is suspicious and for finding clues to reputation have changed.

Since many typical sources of information are no longer available, we have to be creative, consider a greater variety of inputs, and filter the inputs based on providers' practices and policies. Putting these inputs together, we can start to characterize subdomains of public apex domains.

Our detectors currently focus on subdomains of a half dozen public apex domains chosen for evaluation largely based on how often their subdomains are reported by our other detectors. The detector identifies an average of over 300 new subdomains per day (shown in Figure 2).
![Image 2 is a chart ranging from mid-December 2022 to mid-January 2023, showing the average over time of newly detected subdomains, which is over 300. There are peaks in late December and early January.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-2.png) Figure 2. Number of newly detected subdomains per day.

Subdomains detected include those used for sites serving various scams, adult content, and other questionable or malicious content. Two of the more interesting cases we observed include a large-scale SMS phishing campaign and a free Robux scam.

### Case One: SMS Phishing

For several months, our system has detected subdomains of duckdns\[.\]org involved in a campaign to distribute malware and steal credentials. The threat actor group [Roaming Mantis](https://blog.sekoia.io/ongoing-roaming-mantis-smishing-campaign-targeting-france/) runs the campaign, which targets mobile device users in several countries.

An attack typically starts with SMS phishing messages, and it is designed to have victims install the [MoqHao malware](https://www.team-cymru.com/post/moqhao-part-2-continued-european-expansion) (Android users) or to steal victims' credentials (iPhone users). Attackers use geofencing to ensure only visitors from the target regions reach the landing page.

The attack regularly evolves. In mid-2022, we observed a portion of the campaign targeting au ID users. An [au ID](https://id.auone.jp/id/pc/guide/index.html) is an ID created by a Japanese telecommunications provider that allows users to easily perform actions such as accessing account information or making purchases.

Originally, the attack was different for Android and iPhone users, but after several weeks, we observed a change in the strategy. Figure 3 shows the structure of the campaign when we originally observed it (March 2022).
![Image 3 is a tree diagram showing the structure of an observed Roaming Mantis campaign in March 2022. It starts with an automatic redirect. There are different outcomes depending on whether the target is using an Android or an iPhone.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-3.png) Figure 3. Structure of Roaming Mantis campaign observed in March 2022.

The attack started with a web page that automatically redirected users. On the second page, the user was redirected based on the user agent (shown in Figure 4).
![Image 4 is a screenshot of many lines of code that show the redirection of the user dependent on Android or iPhone.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-4.png) Figure 4. Redirection based on user agent.

If the user agent was iPhone, the visitor was redirected to a login page posing as an au ID login, but it was actually located at a duckdns\[.\]org DGA-like subdomain (shown in Figure 5a). If the user agent was Android, victims were redirected to a page where they are encouraged to install a service that was purported to detect annoying or fraudulent SMS and calls (shown in Figure 5b). Again, this page looked similar to those belonging to au ID, but it was located at a DGA-like duckdns\[.\]org subdomain.
![Image 5a is a screenshot of a fake login page that iPhone users were sent to.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-5.png) Figure 5a. Fake login page to which iPhone users were originally sent. ![Image 5b is a screenshot of a fake login page that Android users were sent to. It shows a warning popup that encourages the user to download software.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-6.png) Figure 5b. Page to which Android users were redirected, encouraging users to download software.

By early June 2022, the attack had changed as shown in Figure 6, and victims using both Android and iPhone ended up at the same page.
![Image 6 is a tree diagram showing the structure of an observed Roaming Mantis campaign in June 2022. Unlike the campaign of March 2022, it ends with both iPhone and Android users getting a request for payment. It starts with an automatic redirect.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-7.png) Figure 6. Structure of Roaming Mantis campaign observed in June 2022.

In this version of the campaign, the page with the agent-based redirect still appeared in the chain, but both redirects led to pages with the same message. This page informed visitors they have an unpaid balance in electricity charges, and warned that their power would be stopped if they did not pay immediately (shown in Figure 7a).

Following the link to make the payment led to another page with a form in which visitors could fill in information for V-Preca (prepaid Visa) cards in order to make payments for the fake charges (shown in Figure 7b). The payments, of course, go to the attacker.
![Image 7a is a screenshot of a page requesting payment for a fake charge for an electricity bill.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-8.png) Figure 7a. Page warning visitors to pay bill. ![Image 7b is a screenshot of a page with a form for visitors to enter payment information. The payment will go directly to the attacker.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-9.png) Figure 7b. Form where visitors can enter V-Preca card information for payment.

### Case Two: Free Robux Generator

Since the middle of December 2022, our detection system has identified over 3,000 subdomains of a popular blog hosting service involved in a phishing campaign targeting Roblox users. Roblox's platform is free, but users can purchase Roblox currency -- called Robux -- to access certain perks in the Roblox virtual world. Until recently, most Roblox users were under the age of 13, and children make up a [large portion](https://twitter.com/Roblox/status/1568286900162801665) of the platform's users. Roblox's site expressly states that there is [no such thing as free Robux](https://en.help.roblox.com/hc/en-us/articles/204262550-Free-Robux-or-Membership-Generators#:~:text=Their%20goal%20is%20to%20take,of%20our%20Terms%20of%20Use.), but that has not stopped scammers from trying to convince people otherwise.

The blogs involved appear to be automatically generated using a few templates, and they include text or images related to Roblox (shown in Figure 8).
![Image 8 is two screenshots side by side. They are examples of blogs using a free Robux (the currency of Robox) scam. Left is a page for Runners Path Codes and right is a page for Fasthink. Both pages seem to have auto-generated content.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-10.png) Figure 8. Examples of blogs used in free Robux scam.

Scripts on these pages redirect automatically to bux\[.\]wellter\[.\]de. Visitors might need to click through browser warnings, but those who do arrive at a page offering free Robux (shown in Figure 9).
![Image 9 is a screenshot of a page that advertises free Robux, with the headline text “Roblox robux generator” and a button to generate.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-11.png) Figure 9. Site advertising free Robux.

After running the generator, visitors are redirected again to a page at appinstallcheck\[.\]com listing several possible tasks users might need to perform in order to complete verification. These tasks include installing software, entering a contest to win money, or using a tool to monitor credit scores (shown in Figure 10).
![Image 10 is a screenshot that shows what happens once the “generate” button is hit in image 10. A page is shown titled “Get Free Robux — Verify” where the user is asked to complete offers with five buttons of different options.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-127096-12.png) Figure 10. After requesting free Robux, users are required to complete two more tasks.

## Conclusion

Systems to detect malicious subdomains of public apex domains cannot simply employ the same approaches traditionally used to detect malicious registered domains. These subdomains have unique characteristics that require defenders to adapt methods to establish subdomain reputation. Developing such methods is an important task for security researchers and network defenders.

Palo Alto Networks assigns detected subdomains of public apex domains to the grayware category through our [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions). These subscriptions include [DNS Security](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/dns-security) and [Advanced URL Filtering](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/url-filtering-features/advanced-url-filtering.html).

## Additional Resources

* [Compromised or Attacker-Owned: A Large Scale Classification and Study of Hosting Domains of Malicious URLs](https://www.usenix.org/conference/usenixsecurity21/presentation/desilva) - Usenix Security, 2021
* [Building a Dynamic Reputation System for DNS](https://dl.acm.org/doi/10.5555/1929820.1929844) - Usenix Security, 2010
* [EXPOSURE: Finding Malicious Domains Using Passive DNS Analysis](https://dl.acm.org/doi/10.1145/2584679) - [ACM Transactions on Information and System Security](https://dl.acm.org/toc/tissec/2014/16/4), 2014

Back to top

### Tags

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")
* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")
* [Web hosting](https://unit42.paloaltonetworks.com/tag/web-hosting/ "web hosting")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Answers to Unit 42 Wireshark Quiz, February 2023](https://unit42.paloaltonetworks.com/feb-wireshark-quiz-answers/ "Answers to Unit 42 Wireshark Quiz, February 2023")

### Table of Contents

* 

### Related Articles

* [Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "article - table of contents")
* [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "article - table of contents")
* [TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development](https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/ "article - table of contents")

## Related DNS Resources

![Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_DNS_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 20, 2026 [#### DNS OverDoS: Are Private Endpoints Too Private?](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/)

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")

* [Networking](https://unit42.paloaltonetworks.com/tag/networking/ "networking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/ "DNS OverDoS: Are Private Endpoints Too Private?")  
  ![Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 3, 2025 [#### Lost in Resolution: Azure OpenAI's DNS Resolution Issue](https://unit42.paloaltonetworks.com/azure-openai-dns-resolution/)

* [Endpoint](https://unit42.paloaltonetworks.com/tag/endpoint/ "endpoint")

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/azure-openai-dns-resolution/ "Lost in Resolution: Azure OpenAI's DNS Resolution Issue")  
  ![Pictorial representation of domain registrations with typos. Illustration of a futuristic city with transparent, holographic buildings and glowing blue and orange lights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/07_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 6, 2025 [#### The Next Level: Typo DGAs Used in Malicious Redirection Chains](https://unit42.paloaltonetworks.com/typo-domain-generation-algorithms/)

* [Domain Generation Algorithms](https://unit42.paloaltonetworks.com/tag/domain-generation-algorithms/ "Domain Generation Algorithms")

* [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/ "Malicious Domains")

* [Newly Registered Domain](https://unit42.paloaltonetworks.com/tag/newly-registered-domain/ "Newly Registered Domain")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/typo-domain-generation-algorithms/ "The Next Level: Typo DGAs Used in Malicious Redirection Chains")  
  ![Pictorial representation of detecting and blocking malicious traffic distribution systems. A digital illustration of a glowing globe centered on North America, surrounded by multiple smaller globes, all connected with lines on a dark blue high-tech background, representing global connectivity and network technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/03_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 5, 2025 [#### Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems](https://unit42.paloaltonetworks.com/detect-block-malicious-traffic-distribution-systems/)

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")

* [Redirection](https://unit42.paloaltonetworks.com/tag/redirection/ "Redirection")

* [Web attacks](https://unit42.paloaltonetworks.com/tag/web-attacks/ "web attacks")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/detect-block-malicious-traffic-distribution-systems/ "Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems")  
  ![Pictorial representation of detecting DNS hijacking. Digital illustration of a futuristic data center with glowing blue server racks connected by light beams, surrounded by cloud computing icons, set against a dark background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 4, 2024 [#### Automatically Detecting DNS Hijacking in Passive DNS](https://unit42.paloaltonetworks.com/detect-dns-hijacking-passive-dns/)

* [Domain hijacking](https://unit42.paloaltonetworks.com/tag/domain-hijacking/ "domain hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/detect-dns-hijacking-passive-dns/ "Automatically Detecting DNS Hijacking in Passive DNS")  
  ![Pictorial representation of DNS tunneling detection. Digital illustration of a padlock icon symbolizing cybersecurity, superimposed on a grid comprised of interconnected glowing lines and dots, depicting a global network.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/10/08_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 4, 2024 [#### No Way to Hide: Uncovering New Campaigns from Daily Tunneling Detection](https://unit42.paloaltonetworks.com/detecting-dns-tunneling-campaigns/)

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [DNS tunneling](https://unit42.paloaltonetworks.com/tag/dns-tunneling/ "DNS tunneling")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/detecting-dns-tunneling-campaigns/ "No Way to Hide: Uncovering New Campaigns from Daily Tunneling Detection")  
  ![A visual representation of top level domain tracking. Close-up view of a modern data center with rows of illuminated server racks.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/10_DNS_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 30, 2024 [#### TLD Tracker: Exploring Newly Released Top-Level Domains](https://unit42.paloaltonetworks.com/tracking-newly-released-top-level-domains/)

* [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/ "Malicious Domains")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/tracking-newly-released-top-level-domains/ "TLD Tracker: Exploring Newly Released Top-Level Domains")  
  ![A pictorial representation of deepfake scams. A digital fingerprint integrated into a blue circuit board with glowing lights, illustrating concepts of cybersecurity and technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/11_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 29, 2024 [#### The Emerging Dynamics of Deepfake Scam Campaigns on the Web](https://unit42.paloaltonetworks.com/dynamics-of-deepfake-scams/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Scams](https://unit42.paloaltonetworks.com/tag/scams/ "Scams")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dynamics-of-deepfake-scams/ "The Emerging Dynamics of Deepfake Scam Campaigns on the Web")  
  ![A pictorial representation of using autoencoders to detect malicious DNS traffic. Three transparent blocks with glowing letters "D," "N," and "S" on a circuit board background with blue and purple lighting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/01_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 21, 2024 [#### Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic](https://unit42.paloaltonetworks.com/profiling-detecting-malicious-dns-traffic/)

* [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/ "Malicious Domains")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [Machine Learning](https://unit42.paloaltonetworks.com/tag/machine-learning/ "Machine Learning")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/profiling-detecting-malicious-dns-traffic/ "Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic")  
  ![Conceptual illustration of a digital data center with glowing blue networks and holographic clouds above server racks, representing cloud computing infrastructure and data storage.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) May 13, 2024 [#### Leveraging DNS Tunneling for Tracking and Scanning](https://unit42.paloaltonetworks.com/three-dns-tunneling-campaigns/)

* [DNS tunneling](https://unit42.paloaltonetworks.com/tag/dns-tunneling/ "DNS tunneling")

* [Scanning](https://unit42.paloaltonetworks.com/tag/scanning/ "scanning")

* [Tracking](https://unit42.paloaltonetworks.com/tag/tracking/ "tracking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/three-dns-tunneling-campaigns/ "Leveraging DNS Tunneling for Tracking and Scanning")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
