[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/unit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Confucius Says...Malware Families Get Further By Abusing Legitimate Websites

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 9 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Tom Lancaster](https://unit42.paloaltonetworks.com/author/tom-lancaster/)
  * [Micah Yates](https://unit42.paloaltonetworks.com/author/micah-yates/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 28, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Confucius](https://unit42.paloaltonetworks.com/tag/confucius/)
  * [Quora](https://unit42.paloaltonetworks.com/tag/quora/)
  * [Yahoo](https://unit42.paloaltonetworks.com/tag/yahoo/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites/?pdf=download&lg=en&_wpnonce=f6e4b1f2e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites/?pdf=print&lg=en&_wpnonce=f6e4b1f2e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Confucius%20Says...Malware%20Families%20Get%20Further%20By%20Abusing%20Legitimate%20Websites&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites%2F&title=Confucius%20Says...Malware%20Families%20Get%20Further%20By%20Abusing%20Legitimate%20Websites "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites%2F&text=Confucius%20Says...Malware%20Families%20Get%20Further%20By%20Abusing%20Legitimate%20Websites "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Confucius%20Says...Malware%20Families%20Get%20Further%20By%20Abusing%20Legitimate%20Websites%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites%2F "Share in Mastodon")

### Introduction

When malware wants to communicate home, most use domain names, allowing them to resolve host names to IP addresses of their servers. In order to increase the likelihood of their malware successfully communicating home, cyber espionage threat actors are increasingly abusing legitimate web services, in lieu of DNS lookups to retrieve a command and control address. This negates the requirement to make DNS requests for domains that may be considered malicious and are therefore blocked. For attackers, that's an advantage because it allows their initial communications channel to be obscured amongst other traffic to legitimate services.

This blog post examines two similar malware families that utilize the aforementioned technique to abuse legitimate websites, their connections to each other, and their connections to known espionage campaigns. The first of which we call 'CONFUCIUS\_A', a malware family that has links to a series of attacks associated with a backdoor attack method commonly known as [SNEEPY](https://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=TrojanSpy:Win32/Sneepy.A) (aka ByeByeShell) first reported by Rapid7 in 2013. The second of which we call 'CONFUCIUS\_B', which has a loose link to the series of attacks associated with [Operation Patchwork](https://www.cymmetria.com/wp-content/uploads/2016/07/Unveiling-Patchwork.pdf) and [The Hangover Report](https://www.bluecoat.com/security-blog/2013-05-20/hangover-report).

### Confucius says... resolve your command and control domains using web services.

In 2013, Rapid7 reported on a series of relatively amateur attacks against Pakistani targets. For a long time after the report was published, little changed in how the attackers operated. Although many of the attacks we see today from the group remain the same, we began observing a new backdoor, CONFUCIUS\_A, being dropped by the attackers starting in early 2014. Specifically, the command and control addresses used across multiple SNEEPY samples were being used by CONFUCIUS\_A samples. In the case of just one or two samples, without temporal overlap, this may not be deemed a strong link to CONFUCIUS\_A, however it occurs across a great deal of the infrastructure we have observed.

In most cases where we have been able to identify the droppers, the attack begins with an executable file being sent directly to targets via e-mail. Occasionally the attackers leverage builders for known document exploits, but most of the time they still use self-extracting binaries. The themes of the phishing e-mails vary according to the target, but invariably the file is compiled with an icon that matches the expected content. Examples of the themes used in attacks using CONFUCIUS\_A and the surrounding cluster of activity include:

* Invitations to events relevant to the recipients
* Pornographic material
* Fake updates to popular software products
* News content
* Political content

We have limited evidence of who the targets are, but they appear to primarily be based in the Middle East and parts of Asia, with a focus on Pakistan. In addition to those targets, there are occasional targets seen at enterprises across the globe.

Early samples of the CONFUCIUS\_A malware did not use any legitimate web services for DNS resolution; however, more recent samples of the CONFUCIUS\_A malware use a range of legitimate web services to resolve command and control addresses, the highest profile of which are Yahoo and Quora. The malware was given its name based on the content of one of the first pages we saw being retrieved to determine a command and control address, which is written in the style of a 'Confucius says' joke. See Figure 1.

[![confucious\_1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucious_1-500x356.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucious_1.png)

*Figure 1 -- An example of Quora page contacted by the malware.*

Sometimes malware communicates with legitimate web services simply to perform a connectivity check, but in this case the page was too specific to suggest that was what the attackers were doing. So we decided to investigate how the malware processed the resulting content.

### If this is the question, what is the answer?

For the purposes of illustrating how the command and control address is decoded we will look at the sample with SHA256: a21b956e1be9dcfa8a28c38dc0bb0657508b5588bcf1435052700aea22910d7d. This sample of the malware requests the page shown below in order to determine what IP to POST to.

[![confucius\_2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_2-500x470.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_2.png)

*Figure 2 -- The Quora page contacted by the malware to retrieve its command and control address.*

Reading through the answer, it all makes sense until the section highlighted is reached. By looking at the underlying code, we found that CONFUCIUS\_A is looking for keywords between the phrases "suggested options are" and "hope it will help" and decoding the interim phrase. The decoding is done using a simple lookup table, as shown in ***Figure 3.***

[![confucius\_3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_3-500x258.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_3.png)*Figure 3 -- A memory dump from a CONFUCIUS\_A sample showing the lookup table used by the malware, the table is truncated for presentation purposes.*

The lookup table begins with the marker for the beginning and end of the useful content, and then contains 255 words, each of which corresponds to a number (for example prudent == 255). Using this lookup table in memory it can then derive the command and control address from the text between the markers, "fill plate clever road" becomes 91.210.107\[.\]104.

[![confucius\_4](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_4-500x64.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_4.png)

*Figure 4 *--* HTTP POST request made to command and control server*

### Additional malware contacting Yahoo and Quora

During our investigation into the CONFUCIUS\_A malware, one of the ways we tried to identify variations of the backdoor was by looking for samples that communicated with the same legitimate services as known CONFUCIUS\_A samples. In doing so, we encountered another set of samples exhibiting very similar behavior, which we refer to as CONFUCIUS\_B, due to their similarity, and their likely similar origins. Unfortunately, we have fewer details about how CONFUCIUS\_B malware is delivered or the targets it intends to hit.

For the purposes of this write-up we will follow the chain of dropped files from the dropper with SHA256: 627724fa447e3937f3cdc5388285935a52d6970a616f4ac3d02e583d160cbfc0.

### Enter CONFUCIUS\_B...

At first glance CONFUCIUS\_B looks very similar to CONFUCIUS\_A, and they are also packaged in plain SFX binary files. The CONFUCIUS\_B executable is disguised as a PowerPoint presentation, using a Right-To-Left-Override (RTLO) trick and a false icon. When executed, the self-extracting RAR package drops four files to the %AppData% folder, as shown in Figure 5.

[![confucius\_5](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_5-500x82.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_5.png)

*Figure* *5* **--* The files dropped by CONFUCIUS\_B*

Fancy.vbs executes fancy.bat, which in turn opens the presentation and runs the second stage executable svchost.exe. As with CONFUCIUS\_A, the initial beacons from this svchost.exe are also to Yahoo and Quora, but the pages contacted, whilst odd did not contain any obvious markers, rather they appeared to be entirely gibberish:

[![confucius\_6](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_6-500x484.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_6.png)

*Figure* *6* *-- An exemplary Quora page contacted by the malware.*

So far, the execution chain, involving an SFX RAR and multiple scripts is similar to some samples of SNEEPY, which we associate with CONFUCIUS\_A, but this is where the similarities between CONFUCIUS\_A and CONFUCIUS\_B begin to diverge. Svchost.exe has a custom obfuscation scheme not seen in CONFUCIUS\_A. This obfuscation allows us to quickly identify all of the CONFUCIUS\_B variants; their hashes are included at the end of this post. The obfuscation routine is given in Figure 7.

[![confucius\_7](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_7-500x931.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_7.png)

*Figure 7 -- The obfuscation routine shared across all CONFUCIUS\_B samples.*

Underneath that custom obfuscation lies a UPX packed executable which contains the Yahoo and Quora functionality that originally piqued our interest. After unpacking the UPX code, we began reverse engineering the resulting binary to see how CONFUCIUS\_B interacted with the Yahoo and Quora pages it initially requested. We discovered that CONFUCIUS\_B pieces together its DNS resolution from keywords in the Yahoo and Quora posts similar to that of CONFUCIUS\_A.

CONFUCIUS\_B takes certain keywords in the Quora and Yahoo pages and applies them to a lookup table in memory. Using that lookup table an IP address to POST to is derived. The way this is done can be seen in a memory dump from the running process when it contacts a relevant address, for example as shown in Figure 8.

[![confucius\_8](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_8-500x328.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_8.png)

*Figure 8 -- A memory dump of a CONFUCIUS\_B illustrating the lookup table and initial beacon address.*

The lookup table takes key words and assigns them numbers, or a '.' character, in order to build an IP address, and is arranged as shown in **Table *1***.

*** ** * ** ***

|---------|---|
| love    | 0 |
| hate    | 1 |
| fire    | 2 |
| couple  | 3 |
| green   | 4 |
| weed    | 5 |
| block   | 6 |
| party   | 7 |
| natural | 8 |
| hopeful | 9 |
| or      | . |

*** ** * ** ***

*Table 1 -- Lookup table used by the malware to determine it's command and control address.*

By applying the lookup table to the Quora page shown in Figure 6, we can derive the IP the malware will POST to next for further communications.  
[![confucius\_9](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_9-500x74.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_9.png)

Using our lookup table, giving us an address of 149.202.110\[.\]2:

[![confucius\_10](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_10-500x86.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucius_10.png)

This method of substituting words for components of an IP address, and the repeat use of Yahoo and Quora are novel, which suggest it is likely that the same malware author, or group of malware authors, authored both backdoors.

### Link to Patchwork and test samples

The domain "com-account-jfnjkr\[.\]xyz" is linked to the CONFUCIUS\_B attacks as it was a C2 for the sample c975954fbb473ed8ce3a98ca2c4977bf22d2413db01eda87599524969565836f, which downloads CONFUCIUS\_B. On May 24, 2016, the same domain hosted the sample 8cfd559756630d967bb597b087af98adc75895a1ec52586d53a2d898e4a6e9b0; a basic file stealer malware associated with the Patchwork attackers, via a shared mutex: {9754893678976458374658764387563876}.

All of the CONFUCIUS\_B samples share the same mutex, "rCkBs1Uj493NaMXYY1LZ". Pivoting through samples in Palo Alto Networks AutoFocus, we were able to find what appears to be an early test sample of the malware that creates the same mutex; the SHA256 of the sample is 0bd7db12ba8d9ce9d29983ef76205864dce146eb14cebe32a3431f994cc770ee. We believe it is a test sample, as the configured command and control domain for this sample is 'breachframework\[.\]com'. This can also be linked back to known CONFUCIUS\_B sample via a shared SSL certificate. Breachframework\[.\]com previously resolved to 5.135.85\[.\]16, which used the certificate f6438919d27d08aa545e2f90b58d445cccac6c09, the same certificate was used by 104.23.35\[.\]15, a known command and control address for CONFUCIUS\_B. These relationships are summarized in Figure 9.

[![confucious\_11](http://blog.paloaltonetworks.com/wp-content/uploads/2016/09/Confucious_11-500x350.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2016/09/Confucious_11.png)

*Figure* *9* *-- An overview of the link to the test infrastructure.*

### Conclusion

In this blog post, we discussed two separate malware variations that behave in very similar ways and use similar techniques to acquire a C2 address, with both using Yahoo Answers and Quora to evade traditional mechanisms for blocking command and control domains. Although we cannot link the two clusters of activity by their infrastructure, the technique used to resolve domains is unusual. We also believe that both clusters of activity have links to attacks with likely Indian origins, the CONFUCIUS\_A attacks are linked to the use of SNEEPY/BYEBYESHELL and the CONFUCIUS\_B have a loose link to Hangover. The two malware families themselves are also very similar, and therefore we think that the shared technique is an indication of a single developer, or development company, behind both CONFUCIUS\_A and CONFUCIUS\_B. It is likely that the two clusters of activity are operated by two different operators; however, as the command and control infrastructure used by each cluster differs in the choices of hosting providers.

Palo Alto Networks AutoFocus customers can further explore these malware families and related campaigns with the tags:

* [Confucious\_A](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Confucious_A)
* [Confucious\_B](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Confucious_B)
* [ApacheStealer](https://autofocus.paloaltonetworks.com/#/tag/Unit42.ApacheStealer)
* [Sneepy](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Sneepy)

All samples discussed in the blog and those in the appendix are detected as malicious by Wildfire.

IPS customers are protected by IPS signature 14150.

Exemplary hashes, command and control domains and resolver URL's are given below.

**SHA256 List:**

|------------------------------------------------------------------|---------------------|
| 8cfd559756630d967bb597b087af98adc75895a1ec52586d53a2d898e4a6e9b0 | APACHESTEALER       |
| fb9064abd562012f7c4ffec335f1b669d7ffa0ce724b81f83840474e544c0113 | DEMO\_CONFUCIUS\_B    |
| 0bd7db12ba8d9ce9d29983ef76205864dce146eb14cebe32a3431f994cc770ee | DEMO\_CONFUCIUS\_B    |
| ec15a7698eed7a925b0c074239a92b9f3efdd1054ea281fa914c0bf63d73d319 | CONFUCIUS\_A         |
| 09fcb9444b415781d1d01d0b43c37df441a381042a3f2f91f04890b9c4632c5e | CONFUCIUS\_A         |
| 487d43f38006a609715f95d2e8dd605446de820cafcc453d57a452bc67972a7a | CONFUCIUS\_A         |
| a21b956e1be9dcfa8a28c38dc0bb0657508b5588bcf1435052700aea22910d7d | CONFUCIUS\_A         |
| 7b9454ac9c96db562c2b961a72aa1fece896cd1633a1ec3139eb75346a086f64 | CONFUCIUS\_B         |
| d0176a1d30827a42dda4f575ede0d2d8ad0f71306e41f67b1d1fe999f0e82838 | CONFUCIUS\_B         |
| dd34f8236b314ce5123fc036c7ae1d0b4ef6da3ae781d639bcc1d5a30b197b2c | CONFUCIUS\_B         |
| c975954fbb473ed8ce3a98ca2c4977bf22d2413db01eda87599524969565836f | CONFUCIUS\_B         |
| 6115b1a37cf58d39010fd19bcf83f73e4eae943d95fcb29f8078c6d0e5c37a56 | CONFUCIUS\_B         |
| 700296a05cbe947e24e04f976db596c2471681e69740593fb5d02e4adbd983be | CONFUCIUS\_B         |
| c66660142d9ba85bb89c8277447f3c21d0a7d1ee12fd38cd61091ed02ffba80e | CONFUCIUS\_B         |
| 627724fa447e3937f3cdc5388285935a52d6970a616f4ac3d02e583d160cbfc0 | CONFUCIUS\_B         |
| 248010893646d292254efb4c575b1bfd58d8b75deee38af8616e9e83b695833a | CONFUCIUS\_A (early) |
| 28fd73965f766ab400b655b2c3ffb7c2949112c3c3d9cf05639a382c84828f12 | CONFUCIUS\_A (early) |
| 2f3005a06cf6819690da987414e7db797ad1955861be6f3a8a89e689602fd022 | CONFUCIUS\_A (early) |
| 4462454586b2969821e4b97d0d4387624cd9854ffc9e16750b5771990a707af8 | CONFUCIUS\_A (early) |
| 50f0bf106781452d20f12a33df04e1ebc2d805c9721df83169af3cf394198434 | CONFUCIUS\_A (early) |
| 86f9a01dca754ff0e2c1108dba2cebaab4483b122be1e312f0b24643b1523b49 | CONFUCIUS\_A (early) |
| 9e90f9acb9752e2dc7faa28b7d07330bae69431a1055697420b165521f6768e3 | CONFUCIUS\_A (early) |
| e93dd106f5c031e773f6f490a6df6ef165a0782072c98702a741433b62375829 | CONFUCIUS\_A (early) |
| 51a3758eaf22a893c1771aa70e78e22b775243424abce755dd48cc83879ddd94 | CONFUCIUS\_A (early) |
| 1220815b09694b522a33a4feacfc20ca90e03728c9f5e2bd4288e67e2e1257de | SNEEPY              |
| 1b682fa08d99b1f57e545cab2e0cd553282682f7706a72afe5ee63264002e010 | SNEEPY              |
| 63e0cf48e461ea6e2663fcbb5727e02b39641c86c2860e979a353b3e997eb8d7 | SNEEPY              |
| 7ec2de26d9564f60bb079fbf66e7ce7ff9fe5331937137e3b836023fde7ac1b1 | SNEEPY              |
| 83718971c1cc94ff4cd7b430e57d3d5b61d1032028c23aee56b7148bb6f176c2 | SNEEPY              |
| a50808054fcf359eea0f684b9f84a4ac12e2bf1467a4c33446f7445a4b3bafaa | SNEEPY              |
| 0082b8b2b7ac562db544fd81b26229fd2a6a6c04a9c86123cbd89a285eeb2594 | SNEEPY              |
| 3181065099986c2bb8b3f58f04f2c59e5bd5887dc46f6e7c9a62ba7d2ca23758 | SNEEPY              |
| 7699584f996a7e09ce26437113199531db71d01b22711246246da55abbda5410 | SNEEPY              |
| 815ba75ac821b7c656c9c9bc0e663f9570f71bf247e374d60f9142fcc380efad | SNEEPY              |
| 346c08fc3439a0619903ca25ed0b951e07096701eeb094bdab3770611328873e | SNEEPY              |
| 9c5d8b74fd35755570b478737e1298702535d9baf06f69d9954f265c30dcdab6 | SNEEPY              |
| b19cd6ddbb41d9b689eeff1262bd7cd6b9361d95afb79cd6e77f39c5d3581728 | SNEEPY              |
| d718ea92106894c1bfb2273ed7e71c9ad7cec01fa0ae4c2571e5a762e1f26e8d | SNEEPY              |
| d9c4994aed6f4bab5f2bb65fb2cc5f455ee99848d8f49e22b8b1c5ef13f3e78f | SNEEPY              |

**Resolver URL list:**

https://www.quora.com/Is-bingle-hate-and-love-the-green-or-it-fire-couple-fire-tell-  
me-you-like-or-couple-weed-or-hate-weed-with-deedy-love-claggy-1  
https://answers.yahoo.com/question/index?qid=20160301074835AA7cF60\&sort=N  
hxxps://in.answers.yahoo.com/question/index?qid=20160229024628AA4XQ7r  
hxxp://www.nefuri.com/hi\_is\_bingle\_hate\_and\_love\_the\_green\_or\_it\_fire\_couple\_fire\_tell  
\_me\_you\_like\_or\_couple\_weed\_or\_hate\_weed\_with\_deedy\_block\_claggy\_1562153.html  
hxxp://www.answerlib.org/qv/20160229115557AAXc2Ib.html  
hxxps://in.answers.yahoo.com/question/index?qid=20160229115557AAXc2Ib  
hxxps://www.question.com/what-are-the-precautions-for-diphtheria-tetanus-998506.html  
hxxp://findnerd.com/list/view/How-to-make-a-simple-settings-page-in-android/15891/  
hxxp://able2know.org/topic/312620-1  
hxxp://bs71.blog.com/2016/03/01/performing-namaz/  
hxxp://www.linkibl.com/l/define-simple-support-boundary-condition-of-a-beam-solid-  
mechanics  
hxxp://www.education.com/question/working-model-depict-buoyancy/  
hxxp://www.quora.com/Where-can-I-find-Port-de-Vaire  
hxxp://www.fixya.com/support/t25556697-intel\_desktop\_board\_dh67cl\_having\_vga  
hxxp://www.education.com/question/scientist-calculate-distance-planets  
hxxp://technology.blurtit.com/4492774/import-mri-ct-and-microct-data  
hxxp://bs71.blog.com/2016/03/01/performing-namaz/  
hxxp://www.linkibl.com/l/define-simple-support-boundary-condition-of-a-beam-solid-  
mechanics  
hxxps://www.quora.com/Is-bingle-hate-and-love-the-green-or-it-fire-couple-fire-tell-  
me-you-like-or-couple-weed-or-hate-weed-with-deedy-love-claggy-1  
hxxps://www.quora.com/How-fertilization-takes-place-in-Plants

### C2 Addresses:

adhath-learning\[.\]com  
stepontheroof\[.\]com  
ns1\[.\]b3autybab3s\[.\]com  
stilletowheels\[.\]com  
b3autybab3s\[.\]com  
fierybarrels\[.\]com  
mail\[.\]cooperednews\[.\]info  
ns2\[.\]cooperednews\[.\]info  
teensechs\[.\]com  
newstodayreviews\[.\]com  
ns2\[.\]softwares-free\[.\]com  
www\[.\]fierybarrels\[.\]com  
ns1\[.\]cooperednews\[.\]info  
znaniye-onlayn\[.\]com  
cooperednews\[.\]info  
nophoz\[.\]com  
twigreader\[.\]com  
zadnitsa\[.\]com  
bookerstream\[.\]com  
teens3xweb\[.\]com  
romanrugby\[.\]com  
130dozen\[.\]com  
transseksualov\[.\]com  
cutedazzle\[.\]com  
speedeagles\[.\]com  
www\[.\]templetom\[.\]com  
gallopingroses\[.\]com  
didlynews\[.\]info  
ns2\[.\]didlynews\[.\]info  
ns1\[.\]didlynews\[.\]info  
purple-banana\[.\]com  
uchitel-nitsa\[.\]com  
couchypotatoes\[.\]com  
your3x\[.\]com  
trk\[.\]greatleonidas\[.\]com  
greatleonidas\[.\]com  
chucknorr\[.\]com  
tangyball\[.\]com  
templetom\[.\]com  
younghogs\[.\]com  
www\[.\]cutedazzle\[.\]com  
neistovo\[.\]com  
roseauster\[.\]com  
www\[.\]gallopingroses\[.\]com  
onepickle\[.\]com  
wond3rfulworld\[.\]com  
ns2\[.\]b3autybab3s\[.\]com  
softwares-free\[.\]com  
www\[.\]romanrugby\[.\]com  
gomadweb\[.\]com  
wetcottonballs\[.\]com  
ns1\[.\]softwares-free\[.\]com  
sechshun8\[.\]com  
newsscrapper\[.\]com  
jobs\[.\]undp\[.\]tangyball\[.\]com  
news-letters-4u\[.\]com  
magzinehog\[.\]com  
jupanto\[.\]com  
www\[.\]tumblebin\[.\]com  
little-nuts\[.\]com  
fullhalfempty\[.\]com  
mysugarbin\[.\]com  
ftp\[.\]wond3rfulworld\[.\]com  
blog\[.\]younghogs\[.\]com  
ww2\[.\]younghogs\[.\]com  
www\[.\]younghogs\[.\]com  
ww1\[.\]younghogs\[.\]com  
mx2\[.\]newstodayreviews\[.\]com  
mx1\[.\]newstodayreviews\[.\]com  
mx3\[.\]newstodayreviews\[.\]com  
www\[.\]onepickle\[.\]com  
quicktime\[.\]softwares-free\[.\]com  
tumblebin\[.\]com  
ns1\[.\]bidux\[.\]com\[.\]avtofrom\[.\]us  
www\[.\]nophoz\[.\]com  
breachframework\[.\]website  
breachframework\[.\]com  
com-account-jfnjkr\[.\]xyz  
104\[.\]219\[.\]250\[.\]204  
216\[.\]189\[.\]148\[.\]125  
149\[.\]202\[.\]110\[.\]2  
104\[.\]219\[.\]250\[.\]205  
5\[.\]135\[.\]85\[.\]16  
78\[.\]128\[.\]92\[.\]101  
206\[.\]221\[.\]188\[.\]98  
104\[.\]232\[.\]35\[.\]15  
5\[.\]39\[.\]23\[.\]192  
95\[.\]211\[.\]135\[.\]167  
46\[.\]165\[.\]207\[.\]109  
95\[.\]211\[.\]38\[.\]134  
46\[.\]165\[.\]249\[.\]223  
95\[.\]211\[.\]135\[.\]162  
46\[.\]165\[.\]207\[.\]140  
46\[.\]165\[.\]207\[.\]120  
95\[.\]211\[.\]107\[.\]75  
94\[.\]242\[.\]219\[.\]203  
95\[.\]211\[.\]38\[.\]133  
46\[.\]165\[.\]207\[.\]112  
95\[.\]211\[.\]3\[.\]135  
91\[.\]210\[.\]107\[.\]107  
46\[.\]165\[.\]207\[.\]114  
91\[.\]210\[.\]107\[.\]108  
95\[.\]211\[.\]205\[.\]142  
95\[.\]211\[.\]107\[.\]71  
46\[.\]165\[.\]207\[.\]116  
95\[.\]211\[.\]135\[.\]168  
46\[.\]165\[.\]207\[.\]134  
46\[.\]165\[.\]207\[.\]98  
46\[.\]165\[.\]207\[.\]113  
46\[.\]165\[.\]207\[.\]138  
94\[.\]242\[.\]219\[.\]199  
46\[.\]165\[.\]207\[.\]142  
46\[.\]165\[.\]207\[.\]99  
95\[.\]211\[.\]107\[.\]72  
95\[.\]211\[.\]38\[.\]135  
46\[.\]165\[.\]207\[.\]132  
46\[.\]165\[.\]207\[.\]108
Back to top

### Tags

* [Confucius](https://unit42.paloaltonetworks.com/tag/confucius/ "Confucius")
* [Quora](https://unit42.paloaltonetworks.com/tag/quora/ "Quora")
* [Yahoo](https://unit42.paloaltonetworks.com/tag/yahoo/ "Yahoo")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Sofacy's 'Komplex' OS X Trojan](https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/ "Sofacy’s ‘Komplex’ OS X Trojan")

### Related Articles

* [Recent InPage Exploits Lead to Multiple Malware Families](https://unit42.paloaltonetworks.com/unit42-recent-inpage-exploits-lead-multiple-malware-families/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
