[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [DNS](https://unit42.paloaltonetworks.com/category/dns/ "DNS")  
  [DNS](https://unit42.paloaltonetworks.com/category/dns/)

# TLD Tracker: Exploring Newly Released Top-Level Domains

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 12 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Reethika Ramesh](https://unit42.paloaltonetworks.com/author/reethika-ramesh/)
  * [Wanjin Li](https://unit42.paloaltonetworks.com/author/wanjin-li/)
  * [Daiping Liu](https://unit42.paloaltonetworks.com/author/daiping-liu/)
  * [Zhanhao Chen](https://unit42.paloaltonetworks.com/author/zhanhao-chen/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 30, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [DNS](https://unit42.paloaltonetworks.com/category/dns/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/)
  * [Newly Registered Domain](https://unit42.paloaltonetworks.com/tag/newly-registered-domain/)
  * [Top level domains](https://unit42.paloaltonetworks.com/tag/top-level-domains/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/tracking-newly-released-top-level-domains/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/tracking-newly-released-top-level-domains/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=TLD%20Tracker:%20Exploring%20Newly%20Released%20Top-Level%20Domains&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Ftracking-newly-released-top-level-domains%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Ftracking-newly-released-top-level-domains%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ftracking-newly-released-top-level-domains%2F&title=TLD%20Tracker:%20Exploring%20Newly%20Released%20Top-Level%20Domains "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ftracking-newly-released-top-level-domains%2F&text=TLD%20Tracker:%20Exploring%20Newly%20Released%20Top-Level%20Domains "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ftracking-newly-released-top-level-domains%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=TLD%20Tracker:%20Exploring%20Newly%20Released%20Top-Level%20Domains%20https%3A%2F%2Funit42.paloaltonetworks.com%2Ftracking-newly-released-top-level-domains%2F "Share in Mastodon")

## **Executive Summary**

We investigated 19 new top-level domains (TLDs) released in the past year, which revealed large-scale phishing campaigns, distribution of potentially unwanted programs, torrenting websites, and even pranking and meme campaigns.

We saw correlation between the new TLDs' general availability dates and their popularity, showing that different groups follow the launch of new TLDs and their lifecycle. They do so to initiate domain registration and usage, including for abuse.

There are currently over 1,000 generic top-level domains (TLDs) according to the Internet Assigned Numbers Authority (IANA) root database, and more new TLDs are being added every year. As new TLDs emerge, the potential for malicious activity such as domain squatting and phishing increases tremendously. This is especially problematic when these TLDs resemble the extensions of popular file extensions such as .zip, and distinctive service identifiers such as .bot.

Palo Alto Networks customers are better protected from the threats discussed in this article through our [Network Security](https://www.paloaltonetworks.com/network-security) solutions, such as [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) and [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) subscription services.

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**Malicious Domains**](https://unit42.paloaltonetworks.com/tag/malicious-domains/), [**Newly Registered Domain**](https://unit42.paloaltonetworks.com/tag/newly-registered-domain) |
|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## **New TLDs**

The IANA root database currently lists over 1,000 generic [top-level domains](https://unit42.paloaltonetworks.com/top-level-domains-cybercrime/#post-120952-_llw0ll6i3hu3) (TLDs), with new additions continually being made each year. New TLDs under the [Generic TLD](https://icannwiki.org/Generic_top-level_domain) (gTLD) category are added for myriad reasons including promoting new markets, allowing brands to diversify their web presence, and increasing consumer and business choices.

In the past year and a half, 19 new TLDs have been announced. As more new TLDs are released, companies and other entities may have a hard time keeping up and defensively registering their names on all of them. This presents a possibility for attackers to exploit these TLDs, especially those that resemble file extensions, repurposing them for malicious activities.

## **TLD Rollout Phases**

To understand the potential negative effects of these new TLDs and domain registrations, we first need to understand how new TLDs are rolled out.

All domains under a TLD are tracked in an authoritative database called a [registry](https://www.icann.org/en/icann-acronyms-and-terms/registry-en). A [registry operator](https://www.icann.org/en/icann-acronyms-and-terms/registry-operator-en) is the organization that maintains this authoritative database of all domain names for a particular TLD.

After new TLDs are delegated and approved for future release, the registry operator associated with the new TLD takes responsibility for the different launch and registration phases. A typical set of launch phases will include the following:

* [Sunrise](https://icannwiki.org/Sunrise_Period)
* [Landrush](https://icannwiki.org/Landrush_Period)
* [Early access](https://icannwiki.org/Early_Access_Program)
* [General availability](https://icannwiki.org/General_Availability)

Note that while these phases are typically associated with generic TLDs, only the sunrise period and general availability are mandatory.

### **Sunrise Period**

This is a mandatory phase for all registries. In this phase, registrations are open only to holders of a validated trademark record in the [Trademark Clearinghouse](https://www.trademark-clearinghouse.com/content/what-trademark-clearinghouse) (TMCH). This is an effort to help entities secure domain names under new TLDs that fall under their trademark to protect them from cybersquatting and domain squatting attacks [according to ICANN Wiki](https://icannwiki.org/Sunrise_Period). If more than one entity proves claims to a certain domain, an auction is conducted.

There are two types of sunrise periods:

* End date sunrise (minimum 60-day length)
* The less common Start date sunrise (30-day notice before the start of sunrise period and 30-day minimum length)

### **Landrush**

The landrush phase allows registry operators to make registrations open to the public for specific, premium domain names at a higher cost than their price during general availability. Multiple parties applying for the same domain may lead to an auction.

### **Early Access Period/Program**

Certain TLDs also have an early access period that lasts about a week. Some registry operators may not differentiate between the landrush and early access periods (EAP), and others may offer EAP-like pricing during the first week of general availability.

During the EAP, registrants have the opportunity to register a domain name at a premium price before the TLD's official launch during the general availability period on a first-come, first-served basis. The registry operator may set a premium price that is determined based on the number of days starting from the beginning of this period. The first day of early access has the highest registration price and the last day has the lowest, but both are still higher than the general availability period price.

### **General Availability**

Finally, the TLD is officially launched and moves to a general availability phase where domains under this TLD are available to the public for registration. As mentioned before, some registry operators may offer EAP-like pricing during the first weeks of general availability where domains can be registered for a premium price that slowly drops throughout this period. Typically, a trademark claims phase is in effect in the first 90 days of the general availability period where trademark holders could be alerted when someone registers a domain name matching their trademark.

## **Data Sources**

We track the release of new TLDs through [the official ICANN website](https://www.icann.org/), which reports the sunrise dates for all generic TLDs.

In particular, we are focusing on 19 TLDs that have been released or are in the process of reaching general availability:

* .bot
* .box
* .case
* .channel
* .dad
* .esq
* .foo
* .ing
* .lifestyle
* .living
* .meme
* .mov
* .music
* .nexus
* .phd
* .prof
* .vana
* .watches
* .zip

In April 2024, we gathered data about domains under these TLDs from a variety of sources: [passive DNS](https://unit42.paloaltonetworks.com/connecting-the-dots-in-cyber-threat-campaigns-part-2-passive-dns), [zone file](https://en.wikipedia.org/wiki/Zone_file) data published by registry operators, historical [newly registered domains](https://unit42.paloaltonetworks.com/newly-registered-domains-malicious-abuse-by-bad-actors/) (NRDs) and historical [domain squatting detections](https://unit42.paloaltonetworks.com/cybersquatting/) in these TLDs. Finally, we augment this list by taking the top 1 million most popular domains on the internet using the [Tranco](https://tranco-list.eu/) list---a research-oriented top site ranking. We replace their TLD with each of the 19 new TLDs in an effort to cover all potential cases of abuse of the most popular domain names.

## **Traffic Toward Domains in These New TLDs**

From our customer data logs, Table 1 shows the most-popular new TLDs with the number of unique registered (root) domains.

|---------|----------------------------------|
| **TLD** | **Number of Registered Domains** |
| .zip    | 5,470                            |
| .ing    | 5,071                            |
| .bot    | 4,179                            |
| .mov    | 1,279                            |
| .meme   | 1,175                            |

Table 1. Most popular TLDs from our customer data logs.

We sampled our traffic logs two times a month and added some important dates from the TLD launch schedule as displayed below in Figure 1. This data indicates that the rise in popularity of the top 10 TLDs correlates with the date that a TLD enters the general availability phase.

The .zip TLD entered general availability on May 10, 2023. From the data on May 16, 2023, we see the first spike in the popularity of the .zip domains.

The .ing TLD entered general availability on Dec. 5, 2023. On that same day we saw a large spike in traffic toward .ing domains that has continued since then.

Similarly, Amazon initially allowed registration of .bot domains to customers [exclusively for bot-related services](https://aws.amazon.com/blogs/aws/new-bot-gtld-from-amazon/). After the .bot TLD entered general availability on Oct. 30, 2023, our data reveals notable increases in .bot domain registrations starting on Nov. 1.
![A line graph displaying the growth of internet top-level domains (TLDs) over time, including .bot, .box, .dad, .foo, .mov, .nexus, .zip, .esq, .meme, .img. The graph uses different colors to represent each domain, showing a trend of increasing numbers from left to right along a timeline from May 1, 2023 to April 1, 2024.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/word-image-935275-136515-1.png) Figure 1. Popularity of the top 10 new TLDs at different points over the past year from our logs.

The evident correlation between these new TLDs' availability and the number of domain registrations indicates that various groups or individuals closely follow the launch of new TLDs to register new domains. These groups could include adversaries that plan to abuse domains belonging to these newly available TLDs. Therefore, tracking and conducting security checks for domains under emerging TLDs is crucial.

## **Introducing Our Graph-Based Detection System**

Our graph-based detection system is enabled by a powerful internal graph database that ingests comprehensive cybersecurity data from various data sources including the following:

* [Passive DNS data](https://unit42.paloaltonetworks.com/connecting-the-dots-in-cyber-threat-campaigns-part-2-passive-dns)
* [WHOIS](https://unit42.paloaltonetworks.com/connecting-the-dots-in-cyber-threat-campaigns-part-1-domain-name-whois-information/)
* Third-party threat intelligence sources
* Static and dynamic analysis of malware samples
* Active web crawl data

Leveraging these data sources, we developed a graph-based automated detection system depicted in Figure 2. Starting with a seed list of domains, the system extracts all related data, including associated URLs, IPs and malware samples.

The system generates an independent graph visualization for each seed domain that depicts the relevant relationships with these other associated entities. In this case, the seed list was a list of all domains under these 19 TLDs that we obtained by analyzing information from our previously mentioned data sources.
![Flowchart depicting the process of threat intelligence using a graph database. Starts with 'List of Domains' connecting to 'All associated data', which feeds into a graph database represented by clusters of connected nodes. This leads to 'Potential Attack Campaigns' after 'Multi-stage Pruning and Clustering'. Key symbols include a globe icon for the internet, a cloud for data storage, and various connected nodes representing independent graphs and data interactions.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/word-image-938074-136515-2.png) Figure 2. Graph-based detection system design.

After constructing the graph relations, we conduct a multi-stage pruning and graph clustering process. In this process, our system's pruning algorithm significantly reduces noise and redundancies, only retaining the salient graph paths.

For instance, if a domain uses a globally popular nameserver, then hundreds or thousands of other domains will also use the same nameserver. This results in extra noise added to the graph due to that nameserver node. To address this problem, we prune all paths that are connected to a list of known, benign and popular nodes.

Next, we put these pruned graphs through a clustering process that hunts for commonalities. Our system can cluster domain graphs together based on specific features such as the following:

* Related IP addresses
* Authoritative name servers
* Their WHOIS information
* Domain name lexical patterns
* Traffic and redirection patterns
* TLS certificate information
* Shared or common web infrastructure and content

This process helps us correlate campaigns that share the following traits:

* The same infrastructure
* The same traffic distribution systems
* Downloading and disseminating the same malware samples
* Abusing a common set of intermediary services to broaden their attacks

## **Results: Case Studies**

In this section, we present select network abuse campaigns captured by our graph-based detection system. The results include the following:

* Large-scale phishing attacks
* Distribution of potentially unwanted programs
* Torrenting websites
* Pranking or meme campaigns

### **Redirection Campaign**

Bad actors can leverage trending TLDs and domain names to propagate phishing and redirection attacks. In one such case study, we found that 112 domains belonging to these new TLDs form a tightly related cluster that can be associated with a phishing campaign.

Below, Figure 3 shows the clustered graph for this campaign. The nodes near the middle highlighted in yellow are domains under the newly released TLDs. The red nodes are known malicious indicators that our detectors have already blocked for other suspicious activity or content.

Each blue node represents a relationship between two entities, such as URLs, hostnames, IP addresses and files. Figure 3 reflects four distinct types of relationships in the graph:

* NS records for the domain
* A records for the domain
* Redirect to a URL
* URLs sharing a "path of" relationship with their root domain

At the time of our data collection, all 112 domains redirected to different URL paths under the choto\[.\]xyz domain.
![Network diagram featuring three clusters of nodes connected with lines, indicating relationships among various internet entities including URLs, file samples, hostnames, and IP addresses. The left cluster is colored red, signifying malicious entities, the central cluster is orange, and the right cluster is blue, with each cluster labeled accordingly. A legend explains the color coding and symbols representing different data types and relationships.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/word-image-940694-136515-3-1299x700.png) Figure 3. Redirection campaign with 112 domains from 11 different newly released TLDs.

Although active as recently as April 2024, by May 2024, this traffic coordination domain choto\[.\]xyz was inactive and returned an NXDOMAIN DNS error. Checking our archived scans and web archive data, we find that these paths had redirected users to a gambling website.

We found these 112 domains subsequently redirected to URL paths under choto\[.\]click/vx/\<string\> that redirected to gambling websites. Figure 4 shows an example of one of the gambling pages.
![Screenshot of JoyCasino website homepage featuring a registration form to the left and promotional offers including "WELCOME BONUS UP TO 900%" and "50 FREE SPINS UPON REGISTRATION" displayed on the right side. The background is predominantly purple with decorative golden elements and a spinning roulette wheel image.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/word-image-949140-136515-4.png) Figure 4. Example of a gambling page from this campaign.

All 112 domains share the same four nameservers that are denoted by the nodes on the far right in Figure 3. These nameservers are hosted on the same set of IP addresses, indicating a shared infrastructure.

All 112 domains were also registered with the same registrar, with most registered from June-November 2023. We are the first to detect and block over 78% of these 112 domains according to data from open threat intelligence platforms.

Data from this campaign indicates the group behind it has expanded beyond leveraging newly released TLDs. Our analysis also reveals targeted keywords surrounding recent events. For example, we found at least four new domains relating to the 2024 Summer Olympics are connected to this same campaign.

### **Chat Bot Service Campaign**

Another cluster involved luring victims into scanning a QR code that redirects them to begin texting over SMS. The SMS session can potentially expose the victim to scams, spam, data harvesting campaigns and exposure of personal information.

Shown in Figure 5, this campaign contains 92 different domains belonging to the .bot TLD. The domains in this cluster have distinct naming patterns. They are either:

* A person's first name (such as Akira, Emilia, Mei, Percy or Valentina)
* The name of a city (such as Amsterdam, Leipzig or Toronto)
* Random German words (such as Fluege, Kleinanzeigen, Termin or Welt)
* Random English words (such as Broadband, Chicken or LastMinute)

![Illustration showing a network of connections between different cybersecurity elements such as URLs, file samples, hostnames, IP addresses, and domain names with a seed list. Red connections indicate malicious entities. A flowchart explains how these elements are related, such as redirecting, subdomain creation, and IP resolution.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/word-image-953509-136515-5.png) Figure 5. Homogeneous .bot cluster relating to a chat service campaign with 92 domains.

All of these .bot domains redirected victims to a URL under a different domain ending with the same root name string suffixed by .php.

For example, the domain harriet\[.\]bot redirected to the URL at phpstack-1171166-4096956.cloudwaysapps\[.\]com/harriet.php

Figure 6 illustrates how the picture/avatar displayed and the QR code changes in relation to the domain name queried.

![Two promotional digital artworks displayed on computer screens. On the left, an illustration of a character named Harriet Bot, depicted with flowing hair and wearing a dark pullover, a tie and glasses. On the right, an image of a character named Chicken Bot, styled as a rooster and set against a rural backdrop. Some information is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/F6-786x400.jpg) Figure 6. Two different landing pages under the same domain for URLs ending in harriet\[.\]php and chicken\[.\]php. Similar to the previous campaign, all 92 domains share three nameservers hosted on the same IP address. All 92 domains were registered with the same registrar. Notably, all 92 domains were all registered within a two-week period between Nov. 11, 2023, and Dec. 3, 2023, all within five weeks of the .bot domain entering general availability.

### **Torrenting Unblockit Cluster**

Investigating homogeneous clusters, we found a campaign distributing pirating and torrenting links that contain four domains using the same root name with four different TLDs:

* .esq
* .zip
* .ing
* .foo.

URLs under these domains all have similar paths as well.

Our graph-based analysis reveals that the infrastructure of these torrenting services keeps evolving as its domains are blocked by security vendors. Figure 7 indicates URL paths that redirect users to the same path under a different TLD, possibly as a mirroring phenomenon.
![Diagram showing a network of cybersecurity threats with various types of connections like redirects and subdomains between entities. Red indicates malicious entities. Includes URLS, file samples, hostnames, IP addresses with geolocation, and domains. Key symbols and relationship types are explained in a legend at the bottom.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/word-image-962836-136515-7.png) Figure 7. The unblockit torrenting campaign that highlights the evolving infrastructure.

Following this pattern, we found websites with the root name unblockit under different TLDs. We found 11 additional domains that all redirected to the same unblockit torrenting webpage.

Similar to the above cluster, we found another campaign that uses the root name worldfree4u with different TLDs, which is a torrent and piracy distribution website. Figure 8 shows that we observed the same domain name under five different TLDs:

* .foo
* .meme
* .mov
* .zip
* .dad

Figure 8 reflects a serial chain of redirections of URLs from one domain under one TLD to another.
![Network diagram showing various connections between entities such as URLs, IP addresses, and domain names, with some entities marked in red indicating malicious status. Arrows describe relationships, such as redirection or subdomains. The diagram includes descriptive legends like URL, File/Sample Hash, Hostname, IP address, and Domain in seed list.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/word-image-967611-136515-8.png) Figure 8. Charting the worldfree4u campaign distributing piracy and torrent links.

## **Examining Previously Reported Malicious TLDs and Domains**

Of all the newly released TLDs, .zip and .mov are two TLDs that are among the 10 most popular that also resemble popular file extensions. When Google released these two TLDs for general availability in May 2023, many sources commented on the dangers of these TLDs and how attackers were already leveraging them to perpetuate phishing attacks. Consequently, many of these domains were blocked by security vendors, and new domains under these TLDs began to be scrutinized more carefully.

### **Malware, Critiques and Pranks**

We analyzed previously reported malicious .zip domains and found they have either become NXDOMAINs, parked pages or result in network traffic errors. Some of these previously malicious domains redirect to pages critiquing the TLD, like latestupdate\[.\]zip and googlechrome\[.\]zip. Figure 9 illustrates an example of the critique sites.
![Screenshot of a browser on a web page displaying the text, "really? who thought .zip was a good idea", followed by a facepalm emoji.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/word-image-972508-136515-9-1161x700.jpeg) Figure 9. Example of a previously malicious domain hosting criticism about the .zip TLD.

Websites from domains using the .zip TLD can automatically offer ZIP archives for download. These ZIP archives can contain anything, depending on who established the web server.

Some domains previously reported as malicious now contain prank content. For instance, assignment\[.\]zip downloads a ZIP archive that contains a picture of a leek and one music track (mp3 file), while photos\[.\]zip simply contains the text: "haha you got phished!"

At least two servers using .zip TLD domains previously reported as malicious currently distribute content flagged as malware. The first is eicar-test-file\[.\]zip that appears to send a randomly named ZIP archive containing an EICAR test file.

The second is bomb\[.\]zip, a site that critiques ICANN's decision to approve the .zip TLD. It states "We heard you like zip bombs!" and sends a [zip bomb](https://en.wikipedia.org/wiki/Zip_bomb).

From our studies, we see that many .zip and .mov domains are being used for pranks and memes such as rickrolling.

### **Leveraging TLDs That Look Like File Extensions for Trolling**

We also observe that domains, specifically ones that appear to be file extensions, are [increasingly used for trolling online](https://www.youtube.com/watch?v=dQw4w9WgXcQ). Specifically for [rickrolling](https://www.dictionary.com/e/slang/rickrolling/), we observed 13 domains in this cluster under the TLDs .zip and .mov redirected users to a bit\[.\]ly link that led to a YouTube music video of a 1987 song titled "Never Gonna Give You Up" by musician Rick Astley.

These 13 domains resemble file names such as attachedpdf\[.\]zip and testvideo\[.\]mov. All of them point to the same set of nameservers denoted by the node on the left in Figure 10. They also have the same four IP addresses in their A record, indicated on the right in Figure 10.
![Illustration of a network showing the interaction between various internet elements and an entity identified as malicious, indicated by red. The graphic includes symbols like WWW, user icons, and flags, symbolizing interactions such as redirection and domain resolutions in a web context.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/word-image-975372-136515-10.png) Figure 10. Cluster that points to a link-shortener link that redirects users to get rickrolled.

## **Conclusion**

We investigated domains registered under 19 newly released TLDs from the past year. To sustainably track the evolution of these domains over time, we introduced our graph-based investigation pipeline that can help identify coordinated attack and misuse campaigns.

This article presented detailed case studies on a variety of cyberthreats to show how domains registered on these newly released TLDs have been used for redirection, chatbot campaigns and torrent distribution. As new TLDs emerge, the potential for malicious activity such as domain squatting and phishing increases. This investigation reveals the importance of monitoring domains registered under new TLDs to discover and track new trends and attack campaigns.

Palo Alto Networks [Next-Generation Firewall](https://docs.paloaltonetworks.com/ngfw) customers receive protections against malicious indicators (domain, IP address) mentioned in this article via [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) and [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) subscription services.

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## **Indicators of Compromise**

The following are domains and URL paths related to this article.

* akira\[.\]bot
* amsterdam\[.\]bot
* attachedpdf\[.\]zip
* broadband\[.\]bot
* chicken\[.\]bot
* choto\[.\]click
* choto\[.\]click/vx/
* choto\[.\]xyz
* crowdstrike-hotfix\[.\]zip
* crowdstrikefix\[.\]zip
* emilia\[.\]bot
* fluege\[.\]bot
* harriet\[.\]bot
* kleinanzeigen\[.\]bot
* lastminute\[.\]bot
* leipzig\[.\]bot
* mei\[.\]bot
* percy\[.\]bot
* phpstack-1171166-4096956.cloudwaysapps\[.\]com/chicken.php
* phpstack-1171166-4096956.cloudwaysapps\[.\]com/harriet.php
* termin\[.\]bot
* testvideo\[.\]mov
* toronto\[.\]bot
* unblockit\[.\]black
* unblockit\[.\]esq
* unblockit\[.\]foo
* unblockit\[.\]ing
* unblockit\[.\]zip
* valentina\[.\]bot
* welt\[.\]bot
* worldfree4u\[.\]dad
* worldfree4u\[.\]foo
* worldfree4u\[.\]meme
* worldfree4u\[.\]mov
* worldfree4u\[.\]pm
* worldfree4u\[.\]zip
* assignment\[.\]zip
* photos\[.\]zip
* bomb\[.\]zip
* eicar-test-file\[.\]zip
  Back to top

### Tags

* [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/ "Malicious Domains")
* [Newly Registered Domain](https://unit42.paloaltonetworks.com/tag/newly-registered-domain/ "Newly Registered Domain")
* [Top level domains](https://unit42.paloaltonetworks.com/tag/top-level-domains/ "top level domains")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: The Emerging Dynamics of Deepfake Scam Campaigns on the Web](https://unit42.paloaltonetworks.com/dynamics-of-deepfake-scams/ "The Emerging Dynamics of Deepfake Scam Campaigns on the Web")

### Table of Contents

* 

### Related Articles

* [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ "article - table of contents")
* [The Next Level: Typo DGAs Used in Malicious Redirection Chains](https://unit42.paloaltonetworks.com/typo-domain-generation-algorithms/ "article - table of contents")
* [One Step Ahead in Cyber Hide-and-Seek: Automating Malicious Infrastructure Discovery With Graph Neural Networks](https://unit42.paloaltonetworks.com/graph-neural-networks/ "article - table of contents")

## Related DNS Resources

![Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_DNS_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 20, 2026 [#### DNS OverDoS: Are Private Endpoints Too Private?](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/)

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")

* [Networking](https://unit42.paloaltonetworks.com/tag/networking/ "networking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/ "DNS OverDoS: Are Private Endpoints Too Private?")  
  ![Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 3, 2025 [#### Lost in Resolution: Azure OpenAI's DNS Resolution Issue](https://unit42.paloaltonetworks.com/azure-openai-dns-resolution/)

* [Endpoint](https://unit42.paloaltonetworks.com/tag/endpoint/ "endpoint")

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/azure-openai-dns-resolution/ "Lost in Resolution: Azure OpenAI's DNS Resolution Issue")  
  ![Pictorial representation of domain registrations with typos. Illustration of a futuristic city with transparent, holographic buildings and glowing blue and orange lights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/07_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 6, 2025 [#### The Next Level: Typo DGAs Used in Malicious Redirection Chains](https://unit42.paloaltonetworks.com/typo-domain-generation-algorithms/)

* [Domain Generation Algorithms](https://unit42.paloaltonetworks.com/tag/domain-generation-algorithms/ "Domain Generation Algorithms")

* [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/ "Malicious Domains")

* [Newly Registered Domain](https://unit42.paloaltonetworks.com/tag/newly-registered-domain/ "Newly Registered Domain")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/typo-domain-generation-algorithms/ "The Next Level: Typo DGAs Used in Malicious Redirection Chains")  
  ![Pictorial representation of detecting and blocking malicious traffic distribution systems. A digital illustration of a glowing globe centered on North America, surrounded by multiple smaller globes, all connected with lines on a dark blue high-tech background, representing global connectivity and network technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/03_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 5, 2025 [#### Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems](https://unit42.paloaltonetworks.com/detect-block-malicious-traffic-distribution-systems/)

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")

* [Redirection](https://unit42.paloaltonetworks.com/tag/redirection/ "Redirection")

* [Web attacks](https://unit42.paloaltonetworks.com/tag/web-attacks/ "web attacks")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/detect-block-malicious-traffic-distribution-systems/ "Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems")  
  ![Pictorial representation of detecting DNS hijacking. Digital illustration of a futuristic data center with glowing blue server racks connected by light beams, surrounded by cloud computing icons, set against a dark background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 4, 2024 [#### Automatically Detecting DNS Hijacking in Passive DNS](https://unit42.paloaltonetworks.com/detect-dns-hijacking-passive-dns/)

* [Domain hijacking](https://unit42.paloaltonetworks.com/tag/domain-hijacking/ "domain hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/detect-dns-hijacking-passive-dns/ "Automatically Detecting DNS Hijacking in Passive DNS")  
  ![Pictorial representation of DNS tunneling detection. Digital illustration of a padlock icon symbolizing cybersecurity, superimposed on a grid comprised of interconnected glowing lines and dots, depicting a global network.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/10/08_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 4, 2024 [#### No Way to Hide: Uncovering New Campaigns from Daily Tunneling Detection](https://unit42.paloaltonetworks.com/detecting-dns-tunneling-campaigns/)

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [DNS tunneling](https://unit42.paloaltonetworks.com/tag/dns-tunneling/ "DNS tunneling")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/detecting-dns-tunneling-campaigns/ "No Way to Hide: Uncovering New Campaigns from Daily Tunneling Detection")  
  ![A pictorial representation of deepfake scams. A digital fingerprint integrated into a blue circuit board with glowing lights, illustrating concepts of cybersecurity and technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/11_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 29, 2024 [#### The Emerging Dynamics of Deepfake Scam Campaigns on the Web](https://unit42.paloaltonetworks.com/dynamics-of-deepfake-scams/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Scams](https://unit42.paloaltonetworks.com/tag/scams/ "Scams")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dynamics-of-deepfake-scams/ "The Emerging Dynamics of Deepfake Scam Campaigns on the Web")  
  ![A pictorial representation of using autoencoders to detect malicious DNS traffic. Three transparent blocks with glowing letters "D," "N," and "S" on a circuit board background with blue and purple lighting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/01_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 21, 2024 [#### Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic](https://unit42.paloaltonetworks.com/profiling-detecting-malicious-dns-traffic/)

* [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/ "Malicious Domains")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [Machine Learning](https://unit42.paloaltonetworks.com/tag/machine-learning/ "Machine Learning")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/profiling-detecting-malicious-dns-traffic/ "Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic")  
  ![Conceptual illustration of a digital data center with glowing blue networks and holographic clouds above server racks, representing cloud computing infrastructure and data storage.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) May 13, 2024 [#### Leveraging DNS Tunneling for Tracking and Scanning](https://unit42.paloaltonetworks.com/three-dns-tunneling-campaigns/)

* [DNS tunneling](https://unit42.paloaltonetworks.com/tag/dns-tunneling/ "DNS tunneling")

* [Scanning](https://unit42.paloaltonetworks.com/tag/scanning/ "scanning")

* [Tracking](https://unit42.paloaltonetworks.com/tag/tracking/ "tracking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/three-dns-tunneling-campaigns/ "Leveraging DNS Tunneling for Tracking and Scanning")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
