[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/vice-society-ransomware-powershell/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/vice-society-ransomware-powershell/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Vice Society: A Tale of Victim Data Exfiltration via PowerShell, aka Stealing off the Land

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 16 min read  
Related Products  
[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Ryan Chapman](https://unit42.paloaltonetworks.com/author/ryan-chapman/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:April 13, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [PowerShell Scripts](https://unit42.paloaltonetworks.com/tag/powershell-scripts/)
  * [Vice Society](https://unit42.paloaltonetworks.com/tag/vice-society/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/vice-society-ransomware-powershell/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/vice-society-ransomware-powershell/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Vice%20Society:%20A%20Tale%20of%20Victim%20Data%20Exfiltration%20via%20PowerShell,%20aka%20Stealing%20off%20the%20Land&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fvice-society-ransomware-powershell%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvice-society-ransomware-powershell%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvice-society-ransomware-powershell%2F&title=Vice%20Society:%20A%20Tale%20of%20Victim%20Data%20Exfiltration%20via%20PowerShell,%20aka%20Stealing%20off%20the%20Land "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvice-society-ransomware-powershell%2F&text=Vice%20Society:%20A%20Tale%20of%20Victim%20Data%20Exfiltration%20via%20PowerShell,%20aka%20Stealing%20off%20the%20Land "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvice-society-ransomware-powershell%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Vice%20Society:%20A%20Tale%20of%20Victim%20Data%20Exfiltration%20via%20PowerShell,%20aka%20Stealing%20off%20the%20Land%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fvice-society-ransomware-powershell%2F "Share in Mastodon")

## Executive Summary

During a recent incident response (IR) engagement, the Unit 42 team identified that the [Vice Society ransomware gang](https://unit42.paloaltonetworks.com/vice-society-targets-education-sector/) exfiltrated data from a victim network using a custom built [Microsoft PowerShell](https://learn.microsoft.com/en-us/powershell/) (PS) script. We'll break down the script used, explaining how each function works in order to shed light on this method of data exfiltration.

Ransomware gangs use a plethora of methods to steal data from their victims' networks. Some gangs bring in outside tools, including tools such as FileZilla, WinSCP and rclone. Other gangs use [living off the land binaries and scripts (LOLBAS)](https://lolbas-project.github.io/) methods, such as PS scripts, copy/paste via Remote Desktop Protocol (RDP) and Microsoft's Win32 API (e.g., Wininet.dll calls). Let's examine what happens when a PS script is used to automate the data exfiltration stage of a ransomware attack.

Palo Alto Networks customers receive protections from and mitigations for the script described below in the following ways:

* The XQL query provided below can be used with Cortex XDR to help track the presence of this script.
* The Unit 42 Incident Response team can provide personalized assistance.

Additionally, the [YARA rule](#post-127651-_4d01s3mpq9v1) we attached at the end of this post can be used to detect this script.

| **Related Unit 42 Topics** | [**Vice Society**](https://unit42.paloaltonetworks.com/tag/vice-society/), **[Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)** |
|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------|

## Overview

Threat actors (TAs) using built-in data exfiltration methods like LOLBAS negate the need to bring in external tools that might be flagged by security software and/or human-based security detection mechanisms. These methods can also hide within the general operating environment, providing subversion to the threat actor.

For example, PS scripting is often used within a typical Windows environment. When TAs want to hide in plain sight, PS code is often a go-to.

Early in 2023, the Unit 42 IR team found the Vice Society ransomware gang using a script named w1.ps1 to exfiltrate data from a victim network. In this case, the script was recovered from the Windows Event Log (WEL). Specifically, the script was recovered from an [Event ID 4104: Script Block Logging](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows) event, as found within the Microsoft-Windows-PowerShell/Operational WEL Provider.

While [Script Block Logging must be enabled in Windows](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows?view=powershell-7.3#enabling-script-block-logging) for all script blocks to be logged, Microsoft uses some undocumented back-end magic to record events by default that it deems to be malicious. Thus, Event ID 4104 events can be useful to your analysis even in environments where Script Block Logging has not been fully enabled.

Unit 42 researchers saw the script executed using the following PS command:  
powershell.exe -ExecutionPolicy Bypass -file \\\\\[redacted\_ip\]\\s$\\w1.ps1

|---|------------------------------------------------------------------------------|
| 1 | powershell.exe -ExecutionPolicy Bypass -file \\\\\[redacted\_ip\]\\s$\\w1.ps1 |

This script invocation uses a local domain controller's (DC) IP address within a Uniform Resource Name (URN) path (shown as \[redacted\_ip\] above), specifying the s$ admin share on the DC. Note that, since the script is deployed via one of the client's DCs, target machines could be those that the TA has not yet gained access to directly. As such, any endpoint within the network could become a target for the script. The PS executable is given the -ExecutionPolicy Bypass parameter to bypass any [Execution Policy restrictions](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-executionpolicy).

The script does not require any arguments, as *the onus of what files to copy out of the network is left to the script itself* . Yes, you read that right: The script is automated and thus *chooses*what data should be exfiltrated.

## Script Analysis

The script begins by declaring two constants to be used for victim identification, $id and $token. In the scripts that we identified, these values were hard-coded to "TEST" and "TEST\_1", respectively:  
\[string\]$id = "TEST"; \[string\]$token = "TEST\_1"

|-----|-----------------------------------------------------|
| 1 2 | \[string\]$id = "TEST"; \[string\]$token = "TEST\_1" |

Logically, these variables may be set to more specific values that identify actual victims. We are unsure if this was actually a testing phase or if the values will simply remain in this testing state.

Next, the script declares the functions that serve as the heavy lifters within the code base. Table 1 provides an overview of the script's functions. This lists functions in the order in which they are called, not the order in which they're declared.

|-----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Function**                | **Description**                                                                                                                                                                                                                                                                                                                                                                                             |
| Work( $disk )               | Called for each mounted volume. Identifies directories for potential exfiltration, ignoring a hard-coded list of directory names.  Calls Show() function and passes directory names for all directories that do not match the ignore list.                                                                                                                                                            |
| Show( $name )               | Receives directory names from the Work() function. Chunks directories into groups of five and passes groups of folders to the CreateJobLocal() function for further processing.                                                                                                                                                                                                                             |
| CreateJobLocal( $folders )  | Receives groups of directories, often in groups of five, and creates PowerShell script blocks to be [run as jobs via the Start-Job cmdlet](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/start-job).  Directory names provided go through an inclusion/exclusion process that uses keywords to select which directories to pass to the fill() function to exfiltrate. |
| fill( \[string\]$filename ) | Called by CreateJobLocal() to perform the actual data exfiltration via HTTP POST requests to the threat actor's web server.                                                                                                                                                                                                                                                                                 |

*Table 1. An overview of the script's functions.*

Figure 1 provides an overview of the process flow between functions, helping to highlight how the script functions.
![Image 1 is a function diagram of the w1.ps1 script. It starts with the file and ends with the uploading of the file via HTTP POST events to the threat actor.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-1.png) Figure 1. Function diagram of the w1.ps1 script.

### The Beginning

Before calling any of the declared functions, the script identifies any mounted drives on the system via [Windows Management Instrumentation (WMI)](https://learn.microsoft.com/en-us/windows/win32/wmisdk/wmi-start-page). A call to [get-wmiobject win32\_volume](<https://learn.microsoft.com/en-us/previous-versions/windows/desktop/legacy/aa394515(v=vs.85)>) with some simple filtering provided an array named $drives, which will contain a list of drives mounted on the machine. Each drive path found is then passed to the Work() function individually. Figure 2 shows the associated code snippet.
![Image 2 is a screenshot of a script. Highlighted by 1 is the line starting ForEach-Object and highlighted by 2 is the line starting with Work.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-2.png) Figure 2. The script's preamble code that identifies and then processes each mounted volume.

The following actions are taken in the preamble code:

1. It creates an array named $drives and fills the array with a list of mounted volumes on the host.
   1. The DriveType enum in the win32\_volume references local disks. [See Microsoft's Win32\_Volume Class documentation for more information](<https://learn.microsoft.com/en-us/previous-versions/windows/desktop/legacy/aa394515(v=vs.85)>).
2. It iterates through the identified drives on the host (as $drive), passing each identified drive path to the Work() function.

Figure 3 shows an example of what this code might do on an average Windows host that only has a single drive mounted.
![Image 3 is a screenshot of code. Highlighted in red are the drive and drives variables.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-3.png) Figure 3. Example values for the $drives and $drive variables on a host with a single mounted drive.

For each drive name identified, the preamble calls the Work() function to process directories on the drive.

### Work() Function

Each time Work() is invoked, the function receives a drive path (as $disk) to use for directory searching and processing. Figure 4 shows the beginning of the Work() function.
![Image 4 is a screenshot of many lines of code showing the start of the Work() function. Highlighted are three lines: the array, the $store, and the function.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-4.png) Figure 4. The beginning of the Work() function.

The following actions are taken in the above code:

1. It creates $folders and $jobs arrays.
2. It creates the $store tuple, which stores the above created arrays.
3. It declares the Show() function.

Figure 5 shows the remaining code of the Work() function that resides just beneath the Show() function.
![Image 5 is a screenshot of many lines of code showing the end of the Work() function. Highlighted are three areas.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-5.png) Figure 5. Remainder of the Work() function.

The following actions are taken in the above code:

4. It passes the current volume string to Get-ChildItem and filters out a series of 31 potential directory paths to avoid processing system and/or application-based files. It then passes each root directory name to the Show() function for further processing.
   * For a list of the root directories ignored, see the [Appendix: Inclusions and Exclusions](#post-127651-_46pitawsbgtt) section.
5. After passing the root directory folders to the Show() function, the Work() function recursively searches through sub-directories in the root directories. Similar to the previous filtering, sub-directories that do not match an exclude list are sent to the Show() function for processing.
   * For a list of the root subdirectories ignored, see the [Appendix: Inclusions and Exclusions](#post-127651-_46pitawsbgtt) section.
6. The Show() function creates [PowerShell jobs](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_jobs) to facilitate data exfiltration. The function processes groups of five directories at a time. This section of code serves as a fail safe to ensure that any remaining grouping of folders are processed.
   * For example, if a total of 212 directories are identified, this bit of code would ensure that the final two directories are processed.

### Show() Function

The Show() function receives directory names for processing. Figure 6 provides an overview of the Show() function.
![Image 6 is a screenshot of many lines of code showing an overview of the Show() function. Highlighted are two areas: the line starting with if and the line starting with while.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-6.png) Figure 6. An overview of the Show() function.

The following actions are taken in the above code:

1. The function collects provided directory names until it can create a grouping of five directory names. Once the function has been provided five directory names, it passes them to the CreateJobLocal() function to create PowerShell jobs to facilitate data exfiltration from the directory group.
2. The script implements rate limiting in that it only wants to process up to 10 jobs of five directory groups at one time. Should more than 10 jobs be running, the script sleeps for five seconds and re-checks the number of running jobs.
   * **Note:** This shows a professional level of coding in terms of the overall script design. The script was written to avoid inundating the host's resources. The exact reason for this lies with the author, but the methodology aligns with general coding best practices.

### CreateJobLocal() Function

The CreateJobLocal() function sets up a multi-processing queue for data exfiltration. Figure 7 shows the beginning portion of the CreateJobLocal() function.
![Image 7 is a screenshot of many lines of code showing an overview of the CreateJobLocal() function. Highlighted are two areas: the line starting with if and the line starting with while.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-7.png) Figure 7. An overview of the CreateJobLocal() function.

The following actions are taken in the above code:

1. It creates a pseudo random name for the job being created. Job names will consist of five alpha characters (including lower- and upper-case characters).
   * For example, the following are five job names generated by the script during a random debugging session: iZUIb, dlHxF, VCHYu, FyrCb and GVILA.
2. It sets up a PowerShell job, which has a code structure that will be a script block created at this point in the script.

At this point in CreateJobLocal(), the fill() function is declared. We will return to this shortly. First, we will continue with the remainder of the CreateJobLocal() function. Figure 8 shows the next chunk of this code.
![Image 8 is a screenshot of many lines of code showing the remainder of the CreateJobLocal() function. Highlighted by numbers 3, 4, 5 are the foreach and if sections](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-8.png) Figure 8. Additional code belonging to the CreateJobLocal() function.

The following are descriptions of the above CreateJobLocal() code base:

3. It creates a $fileList array for files to exfiltrate, then loops through directories in the current group (as noted above, it typically processes directories in groups of five).
4. It sets up inclusion and exclusion arrays named $include and $excludes.
   * For a list of the values from these arrays, see the [Appendix: Inclusions and Exclusions](#post-127651-_46pitawsbgtt) section.
5. It loops through directories in the given directory group and filters folders to include based on hard-coded values in the $include array using a regular expression.

At this point, the function uses excludes to filter further the files that should be exfiltrated.
![Image 9 is a screenshot of many lines of code showing the remainder of the CreateJobLocal() function. Highlighted by numbers 6, 7 and 8 are areas of interest: two arrays and the foreach section](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-9.png) Figure 9. Remainder of the CreateJobLocal() function.

The following are descriptions of the remaining CreateJobLocal() code base:

6. **If a directory matches the include list, it finds all files within the directory that do not have extensions found on the exclude list, are larger than 10 KB, and have an extension.**
   * **Note:** Testing confirmed that the script ignores both files that are under 10 KB in size and those that do not have a file extension.
7. Even if a directory does not match the include list via a regular expression match, the directory's files are checked to see if they should be included for exfiltration.
   * This looks to serve as a second chance for files to match the inclusion list, as the comparison is done with the -Include parameter of the Get-ChildItem cmdlet as opposed to the -Like comparison that performs a regex comparison in step 5 above.
8. It loops through the files identified for exfiltration and calls the fill() function to exfiltrate each file.

Figure 10 shows the first group of five folders the scripts selected when run within one of our malware analysis virtual machines (VMs). These values will differ based on the machine on which the script is run. We simply wanted to show where the script began searching for data within our test environment.
![Image 10 is a screenshot of the folders selected by the script for exfiltration. Highlighted in red in the blue bottom pane is the C drive path.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-10.png) Figure 10. An example run of the script showing the first five directories identified for exfiltration.

### Fill() Function

The fill() function performs the actual data exfiltration. This function serves to build the URLs that will be used to exfiltrate files, and it uses a System.Net.Webclient object to perform the actual exfiltration via HTTP POST events using the object's .UploadFile method. Figure 11 shows the fill() function.
![Image 11 is a screenshot of many lines of code showing an overview of the fill(function) function. Highlighted by red numbers showing the order of actions taken by the script.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-11.png) Figure 11. An overview of the fill() function.

The following actions are taken in the above code:

1. Though not technically part of the actual fill() function, the variables $id and $token from the first two lines of the overall script are used within each file upload URL.
2. It builds a $prefix value that includes the two most important indicators of compromise (IoCs) from the script.
   * An IP address
     1. This is the TA's infrastructure / server IP address to which the files will be uploaded.
   * A network port number
     1. This port number may be 80, 443, or it may be a custom port number such as one [normally associated with the ephemeral port range](https://en.wikipedia.org/wiki/Ephemeral_port).

**Note:** For the purposes of this article, we are redacting this information.

3. It instantiates a WebClient object that will be used to perform the HTTP-based data exfiltration.
4. It builds a $fullPath variable, which is the full file path to the file being uploaded.
   * **Note:** This is important because this means that each HTTP POST event will include the file's full path. If you are able to obtain the source host's IP address along with this path, you will then be able to build out a list of exfiltrated files after the fact.
5. It builds the full URL for the file upload, $uri, by combining the $prefix, $token, $id and $fullPath variables.
6. It calls the [WebClient.UploadFile()](https://learn.microsoft.com/en-us/dotnet/api/system.net.webclient.uploadfile) method to upload the file.
   * **Note:** This creates an HTTP POST event.

### Example HTTP Activity

To see what the script's POST requests would look like on the threat actor's web server, we set up a server on a local VM, directed our malware analysis machine to use this VM as its gateway and ran the script. The following are three example POST requests as created by the script when executed within our test environment.  
192\.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fdont\_exfil\_me.eml HTTP/1.1" 200 166 "-" "-" 192.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fi\_mean\_please\_dont\_exfil\_me.eml HTTP/1.1" 200 166 "-" "-" 192.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fme\_either.docx HTTP/1.1" 200 166 "-" "-"

|-------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 | 192.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fdont\_exfil\_me.eml HTTP/1.1" 200 166 "-" "-" 192.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fi\_mean\_please\_dont\_exfil\_me.eml HTTP/1.1" 200 166 "-" "-" 192.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fme\_either.docx HTTP/1.1" 200 166 "-" "-" |

Please note that the 192.168.42\[.\]100 address above is the IP of the test client VM that we used. In a real world scenario, Vice Society's web server would denote the victim's egressing IP address in this location.

Based on the above results, we can garner some important things about the HTTP activity initiated by the script:

1. The fullpath POST parameter does *not* include the drive letter from which the file was sent.
2. The script does not provide a user agent string to the web server.

If you have a network security monitoring (NSM) or intrusion [detection system (IDS) such as Zeek](https://zeek.org/about/), or a packet capture system running in your environment, you might be able to see the outgoing POST requests. Those outgoing logs might reveal the length of the requests in bytes (focus on bytes out versus total bytes), which could help identify which versions of files were exfiltrated.

## Conclusion

Vice Society's PowerShell data exfiltration script is a simple tool for data exfiltration. Multi-processing and queuing are used to ensure the script does not consume too many system resources. However, the script's focus on files over 10 KB with file extensions and in directories that meet its include list means that the script will not exfiltrate data that doesn't fit this description.

Unfortunately, the nature of PS scripting within the Windows environment makes this type of threat difficult to prevent outright. We have provided tips and tricks related to detection and hunting this type of threat in the [Detection and Hunting](#post-127651-_tfjt1juueu3) section. Using these tips, especially using the provided YARA rule, we wish you the best of luck in identifying this threat. Don't let the ransomware gangs automate the loss of your data!

Palo Alto Networks customers receive protections from and mitigations for the script described below in the following ways:

* The XQL query provided below can be used with Cortex XDR to help track the presence of this script.
* The Unit 42 Incident Response team can provide personalized assistance.

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

## Detection and Hunting

* Implement the YARA rule provided in this article within your security systems.
* [Enable PowerShell Module and Script Block Logging in PowerShell](https://www.rootusers.com/enable-and-configure-module-script-block-and-transcription-logging-in-windows-powershell/)
  * Check Windows Event Logs Event IDs 400, 600, 800, 4103 and 4104
  * Search for the script's function names in 4104 events:
    * Work( $disk )
    * Show( $name )
    * CreateJobLocal( $folders )
    * fill( \[string\]$filename )
* Monitor for command lines that include the following: powershell.exe -ExecutionPolicy Bypass -file \\\\\[internal\_ip\_address\]\\s$\\w1.ps1
* Look for HTTP POST events to /upload endpoints on unknown remote HTTP servers.
* Look for HTTP activity direct to external IP addresses, if you have this visibility.
* Detect spikes in network traffic:
  * Do you have a network baseline? Use it to determine when network traffic from a given or set of hosts far exceeds the baseline.
  * Do you have a SIEM, SOAR or log aggregation utility that will allow you to alert on HTTP POST sizes? Perhaps look for when a count of POST events to a given site -- especially an IP address -- exceeds a baseline. Also look into alerting for when a POST event has a request size over a given threshold. For example, you might want to alert when any POST event has a file size \> 10 MB. This will require tuning and insight into what is normal in your environment.
  * Look into network traffic spikes generated by non-expected accounts. For example, should your Domain Admin, Enterprise Admin or general service accounts be making large POST requests? Is this something for which you can generate alerts?

## Indicators of Compromise

Since the script in question was recovered from an Event ID 4104 WEL event, a hash of the true, original file as it may have resided on disk is not available. However, we have included the filename of the script along with the contents recovered from the script in this section.

**Note:** We have opted *not* to release any IP addresses or port numbers. Furthermore, these IoCs will *not*be provided upon request.

### Filename

* w1.ps1

## YARA Rule

The following YARA rule was written to help identify this script. As of this article's publication date, the script only yielded one false positive in [VirusTotal Intelligence's Retro Hunt system](https://support.virustotal.com/hc/en-us/articles/360001293377-Retrohunt) over a one-year period. The rule looks for the two lines of code that set up the victim identity information and the string concatenation methods used to build the URIs used for data exfiltration via HTTP.  
rule vice\_society\_ps\_exfil\_script { meta: author = "RyanChapman - Unit42 - PaloAltoNetworks" date = "2023-02-10" description = "Detects Vice Society's 'w1.ps1' Data Exfiltration PowerShell script. Often run via 'powershell.exe -ExecutionPolicy Bypass -file \\\\\[ip\_address\]\\s$\\w1.ps1'." strings: $victim\_id = /\\\[string\\\]\\$id = \\".{0,1000}\\"/ $victim\_token = /\\\[string\\\]\\$token = \\"{0,1000}\\"/ $uri\_prefix = /\\$prefix = \\'https?:\\/\\/{0,300}:\\d{0,6}\\/upload\\'/ nocase ascii wide $uri\_builder = "$uri = \\"$( $prefix )?token=$( $token )\&id=$( $id )\&fullPath=$( $fullPath )\\"" nocase ascii wide condition: (any of ($uri\*)) or (2 of ($victim\*)) }

|----------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 | rule vice\_society\_ps\_exfil\_script { meta: author = "RyanChapman - Unit42 - PaloAltoNetworks" date = "2023-02-10" description = "Detects Vice Society's 'w1.ps1' Data Exfiltration PowerShell script. Often run via 'powershell.exe -ExecutionPolicy Bypass -file \\\\\[ip\_address\]\\s$\\w1.ps1'." strings: $victim\_id = /\\\[string\\\]\\$id = \\".{0,1000}\\"/ $victim\_token = /\\\[string\\\]\\$token = \\"{0,1000}\\"/ $uri\_prefix = /\\$prefix = \\'https?:\\/\\/{0,300}:\\d{0,6}\\/upload\\'/ nocase ascii wide $uri\_builder = "$uri = \\"$( $prefix )?token=$( $token )\&id=$( $id )\&fullPath=$( $fullPath )\\"" nocase ascii wide condition: (any of ($uri\*)) or (2 of ($victim\*)) } |

## Unit 42 Managed Threat Hunting Queries

config case\_sensitive = false | preset = xdr\_process // Detect powershell command line that contains //\<ip\_address\>/s$/.\*.ps1 | filter action\_process\_image\_name = "powershell.exe" and action\_process\_image\_command\_line ~= "\\\\\\\\((25\[0-5\]|(2\[0-4\]|1\\d|\[1-9\]|)\\d)\\.?\\b){4}\\\\s\[$\]\\\\.\*\[.\]ps1" | fields agent\_hostname, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_command\_line | alter detected\_ip\_address = arrayindex(regextract(action\_process\_image\_command\_line, "\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\b"), 0) | filter incidr(detected\_ip\_address, "10.0.0.0/8") = true or incidr(detected\_ip\_address, "192.168.0.0/16") = true or incidr(detected\_ip\_address, "172.16.0.0/12") = true

|-------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 | config case\_sensitive = false | preset = xdr\_process // Detect powershell command line that contains //\<ip\_address\>/s$/.\*.ps1 | filter action\_process\_image\_name = "powershell.exe" and action\_process\_image\_command\_line ~= "\\\\\\\\((25\[0-5\]|(2\[0-4\]|1\\d|\[1-9\]|)\\d)\\.?\\b){4}\\\\s\[$\]\\\\.\*\[.\]ps1" | fields agent\_hostname, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_command\_line | alter detected\_ip\_address = arrayindex(regextract(action\_process\_image\_command\_line, "\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\b"), 0) | filter incidr(detected\_ip\_address, "10.0.0.0/8") = true or incidr(detected\_ip\_address, "192.168.0.0/16") = true or incidr(detected\_ip\_address, "172.16.0.0/12") = true |

## Additional Resources

* [Vice Society: Profiling a Persistent Threat to the Education Sector](https://unit42.paloaltonetworks.com/vice-society-targets-education-sector) -- Unit 42, Palo Alto Networks
* [2022 Unit 42 Ransomware Threat Report Highlights: Ransomware Remains a Headliner](https://unit42.paloaltonetworks.com/2022-ransomware-threat-report-highlights) -- Unit 42, Palo Alto Networks
* [2022 Unit 42 Ransomware Threat Report](https://start.paloaltonetworks.com/unit-42-ransomware-threat-report.html) -- Unit 42, Palo Alto Networks

## Appendix: Inclusions and Exclusions

### Work() function exclusions

( $_.FullName -notlike "\*old\*" ) ( $_.FullName -notlike "\*Backup\*" ) ( $_.FullName -notlike "\*Delete\*" ) ( $_.FullName -notlike "\*Snap\*" ) ( $_.FullName -notlike "\*Backup\*" ) ( $_.FullName -notlike "\*System\*" ) ( $_.FullName -notlike "\*Windows\*" ) ( $_.FullName -notlike "\*}\*" ) ( $_.FullName -notlike "\*{\*" ) ( $_.FusllName -notlike "\*Symantec\*" ) \<-- Notice the mis-spelling of "FullName" ( $_.FullName -notlike "\*Chrome\*" ) ( $_.FullName -notlike "\*Mozilla\*" ) ( $_.FullName -notlike "\*ESET\*" ) ( $_.FullName -notlike "\*Package Cache\*" ) ( $_.FullName -notlike "\*VMWare\*" ) ( $_.FullName -notlike "\*Microsoft\*" ) ( $_.FullName -notlike "\*Sophos\*" ) ( $_.FullName -notlike "\*System Volume Information\*" ) ( $_.FullName -notlike "\*PerfLogs\*" ) ( $_.FullName -notlike "\*Recovery\*" ) ( $_.FullName -notlike "\*Boot\*" ) ( $_.FullName -notlike "\*Program Files\*" ) ( $_.FullName -notlike "\*ProgramData\*" ) ( $_.FullName -notlike "\*msys64\*" ) ( $_.FullName -notlike "\*apache-ant\*" ) ( $_.FullName -notlike "\*libarchive\*" ) ( $_.FullName -notlike "\*MinGW\*" ) ( $_.FullName -notlike "\*Ruby\*" ) ( $_.FullName -notlike "\*mysql-connector\*" ) ( $_.FullName -notlike "\*svm-map\*" ) ( $\_.FullName -notlike "\*TDM-GCC\*" )

|-------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 | ( $_.FullName -notlike "\*old\*" ) ( $_.FullName -notlike "\*Backup\*" ) ( $_.FullName -notlike "\*Delete\*" ) ( $_.FullName -notlike "\*Snap\*" ) ( $_.FullName -notlike "\*Backup\*" ) ( $_.FullName -notlike "\*System\*" ) ( $_.FullName -notlike "\*Windows\*" ) ( $_.FullName -notlike "\*}\*" ) ( $_.FullName -notlike "\*{\*" ) ( $_.FusllName -notlike "\*Symantec\*" ) \<-- Notice the mis-spelling of "FullName" ( $_.FullName -notlike "\*Chrome\*" ) ( $_.FullName -notlike "\*Mozilla\*" ) ( $_.FullName -notlike "\*ESET\*" ) ( $_.FullName -notlike "\*Package Cache\*" ) ( $_.FullName -notlike "\*VMWare\*" ) ( $_.FullName -notlike "\*Microsoft\*" ) ( $_.FullName -notlike "\*Sophos\*" ) ( $_.FullName -notlike "\*System Volume Information\*" ) ( $_.FullName -notlike "\*PerfLogs\*" ) ( $_.FullName -notlike "\*Recovery\*" ) ( $_.FullName -notlike "\*Boot\*" ) ( $_.FullName -notlike "\*Program Files\*" ) ( $_.FullName -notlike "\*ProgramData\*" ) ( $_.FullName -notlike "\*msys64\*" ) ( $_.FullName -notlike "\*apache-ant\*" ) ( $_.FullName -notlike "\*libarchive\*" ) ( $_.FullName -notlike "\*MinGW\*" ) ( $_.FullName -notlike "\*Ruby\*" ) ( $_.FullName -notlike "\*mysql-connector\*" ) ( $_.FullName -notlike "\*svm-map\*" ) ( $\_.FullName -notlike "\*TDM-GCC\*" ) |

( $_.FullName -notlike "\*Windows\*" ) ( $_.FullName -notlike "\*inetpub\*" ) ( $_.FullName -notlike "\*pris\_temp\*" ) ( $_.FullName -notlike "\*Request\*" ) ( $_.FullName -notlike "\*ESET\*" ) ( $_.FullName -notlike "\*Package Cache\*" ) ( $_.FullName -notlike "\*VMWare\*" ) ( $_.FullName -notlike "\*VMMShare\*" ) ( $_.FullName -notlike "\*Logs\*" ) ( $_.FullName -notlike "\*System Volume Information\*" ) ( $_.FullName -notlike "\*WindowsAzure\*" ) ( $_.FullName -notlike "\*Packages\*" ) ( $_.FullName -notlike "\*Boot\*" ) ( $_.FullName -notlike "\*Program Files\*" ) ( $_.FullName -notlike "\*ProgramData\*" ) ( $_.FullName -notlike "\*.cargo\*" ) ( $\_.FullName -notlike "\*.gradle\*" )

|-------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | ( $_.FullName -notlike "\*Windows\*" ) ( $_.FullName -notlike "\*inetpub\*" ) ( $_.FullName -notlike "\*pris\_temp\*" ) ( $_.FullName -notlike "\*Request\*" ) ( $_.FullName -notlike "\*ESET\*" ) ( $_.FullName -notlike "\*Package Cache\*" ) ( $_.FullName -notlike "\*VMWare\*" ) ( $_.FullName -notlike "\*VMMShare\*" ) ( $_.FullName -notlike "\*Logs\*" ) ( $_.FullName -notlike "\*System Volume Information\*" ) ( $_.FullName -notlike "\*WindowsAzure\*" ) ( $_.FullName -notlike "\*Packages\*" ) ( $_.FullName -notlike "\*Boot\*" ) ( $_.FullName -notlike "\*Program Files\*" ) ( $_.FullName -notlike "\*ProgramData\*" ) ( $_.FullName -notlike "\*.cargo\*" ) ( $\_.FullName -notlike "\*.gradle\*" ) |

### CreateLocalJob() Includes

\[array\]$include = @( "\*941\*", "\*1040\*", "\*1099\*", "\*8822\*", "\*9465\*", "\*401\*K\*", "\*401K\*", "\*4506\*T\*", "\*4506T\*", "\*Abkommen\*", "\*ABRH\*", "\*Abtretung\*", "\*abwickeln\*", "\*ACA\*1095\*", "\*Accordi\*", "\*Aceito\*", "\*Acordemen\*", "\*Acordos\*", "\*Acuerde\*", "\*Acuerdo\*", "\*Addres\*", "\*Adres\*", "\*Affectation\*", "\*agreem\*", "\*Agreemen\*Disclosur\*", "\*agreement\*", "\*Alamat\*", "\*Allocation\*", "\*angreifen\*", "\*Angriff\*", "\*Anmeldeformationen\*", "\*Anmeldeinformationen\*", "\*Anmeldenunter\*", "\*Anmeldung\*", "\*Anschrift\*", "\*Anspruch\*", "\*Ansspruch\*", "\*Anweisung\*", "\*AnweisungBank\*", "\*anxious\*", "\*Análise\*", "\*Apotheke\*", "\*ARH\*", "\*Asignación\*", "\*Asignatura\*", "\*Assegnazione\*", "\*Assignation\*", "\*Assignment\*", "\*Atribuição\*", "\*attorn\*", "\*Audit\*", "\*Auditnaadrese\*", "\*Aufführen\*", "\*Aufgabe\*", "\*Aufschühren\*", "\*Auftrag\*", "\*auftrunken\*", "\*Auftrunkinen\*", "\*Auswertung\*", "\*Avaliação\*", "\*Avaliações\*", "\*Avtal\*", "\*balanc\*", "\*bank\*", "\*Bargeld\*", "\*Belästigung\*", "\*Benef\*", "\*benefits\*", "\*Bericht\*", "\*Beschäftigung\*", "\*Betrug\*", "\*Bewertung\*", "\*bezahlen\*", "\*billing\*", "\*bio\*", "\*biometric\*", "\*borrow\*", "\*Brett\*", "\*Brok\*", "\*Buchstabe\*", "\*budget\*", "\*bully\*", "\*Bund\*", "\*bureau\*", "\*Büro\*", "\*capital\*", "\*card\*", "\*card\*SS\*", "\*cash\*", "\*CDA\*", "\*Cessão\*", "\*cestovnípas\*", "\*check\*", "\*checking\*", "\*claim\*", "\*clandestine\*", "\*Committe\*", "\*compilation\*", "\*comprom\*", "\*compromate\*", "\*compromise\*", "\*concealed\*", "\*Concordam\*", "\*Concordo\*", "\*Concordância\*", "\*Conf\*", "\*confid\*", "\*Confidential\*Disclosure\*", "\*Conflict\*", "\*contact\*", "\*contr\*", "\*convict\*", "\*Court\*", "\*CPF\*", "\*crandestin\*", "\*Cred\*", "\*Credential\*", "\*CRH\*", "\*Crim\*", "\*Crime\*", "\*CSE\*", "\*DACA\*", "\*DDRH\*", "\*dead\*", "\*Dean\*", "\*death\*", "\*Demog\*", "\*Demütigung\*", "\*Department\*", "\*Designação\*", "\*Detail\*", "\*Die\*", "\*Diebstahl\*", "\*Dirección\*", "\*Direktor\*", "\*Disburs\*", "\*Disbursement\*", "\*Disclosure\*Agreement\*", "\*Disclosure\*Confidential\*", "\*discriminate\*", "\*Dohody\*", "\*DRH\*", "\*Déclaration\*", "\*EIN\*", "\*Email\*", "\*E-Mail\*", "\*emplo\*", "\*Endereço\*", "\*Enrol\*", "\*enroll\*", "\*Enterin\*", "\*entrusted\*", "\*Erklärung\*", "\*Ermittlung\*", "\*Ertrittlung\*", "\*Evaluasi\*", "\*Evaluation\*", "\*Evaluierung\*", "\*Ewaluacja\*", "\*Excerpted\*", "\*FATCA\*", "\*federal\*", "\*Finan\*", "\*Finanzen\*", "\*Fiscalización\*", "\*Forbidden\*", "\*Form\*", "\*fraud\*", "\*Free\*", "\*Freeman\*", "\*Frei\*", "\*FSA\*", "\*föderal\*", "\*Geduldig\*", "\*Gefühllos\*", "\*Gehaltsabechung\*", "\*geheim\*", "\*Geheimnis\*", "\*GESetzlich\*", "\*Gewalt\*", "\*Gleichgewicht\*", "\*gov\*", "\*government\*", "\*grantor\*", "\*haras\*", "\*Haushalt\*", "\*hidden\*", "\*hir\*", "\*Hirf\*", "\*Hodnocení\*", "\*HR\*", "\*HRDD\*", "\*Human\*", "\*I\*765\*", "\*i\*9\*", "\*i9\*", "\*identi\*", "\*illegal\*", "\*important\*", "\*Incarico\*", "\*Incident\*", "\*Income\*", "\*Indirizzo\*", "\*individual\*", "\*Info\*", "\*Information\*", "\*informationprivileged\*", "\*Innen\*", "\*insider\*", "\*Insurance\*", "\*Internal\*", "\*Intima\*", "\*investigation\*", "\*invoicing\*", "\*IRS\*", "\*isola\*", "\*ITIN\*", "\*K\*1\*", "\*k\*12\*", "\*K1\*", "\*Karte\*", "\*Kasse\*", "\*Kesepakatan\*", "\*kill\*", "\*klassifiziert\*", "\*kompromet\*", "\*Kontakt\*", "\*Kontoauszug\*", "\*Kontrola\*", "\*Kritik\*", "\*kritisch\*", "\*Kuppel\*", "\*Legal\*", "\*lender\*", "\*letter\*", "\*List\*", "\*loan\*", "\*Login\*", "\*Lohn\*", "\*Lohn-und\*", "\*m\*274\*", "\*mail\*", "\*Mechan\*", "\*Med\*", "\*Menschlich\*", "\*misdemeanor\*", "\*Missbrauch\*", "\*Missão\*", "\*Molecula\*", "\*Morada\*", "\*Moradas\*", "\*MwSt\*", "\*National\*Health\*", "\*NDA\*", "\*Nds\*", "\*NHS\*", "\*nicht\*", "\*notsorted\*", "\*Numb\*", "\*Numero\*", "\*obligat\*", "\*Ocena\*", "\*Offenbarung\*", "\*office\*", "\*order\*", "\*Osoite\*", "\*Osoitteet\*", "\*Partn\*", "\*pas\*", "\*passport\*", "\*passwd\*", "\*password\*", "\*patient\*", "\*PATIENT\*", "\*Pause\*", "\*pay\*", "\*payment\*", "\*payroll\*", "\*Pemeriksaan\*", "\*penalty\*", "\*Pendel\*", "\*pendeln\*", "\*Penugasan\*", "\*Perjanjian\*", "\*Pers\*", "\*person\*", "\*Personnel\*", "\*Pharm\*", "\*Phon\*", "\*Phone\*", "\*Phys\*", "\*porno\*", "\*Porozumienie\*", "\*principal\*", "\*priv\*", "\*priva\*", "\*privit\*", "\*promissor\*", "\*Przydział\*", "\*Przypisanie\*", "\*Prüfbericht\*", "\*Prüfung\*", "\*pwd\*", "\*Přidělení\*", "\*Rechnungsprüfung\*", "\*Rechtliches\*", "\*rechtswidrig\*", "\*Recruitment\*", "\*Recursos\*Humanos\*", "\*RecursosHumanos\*", "\*Regierung\*", "\*Reisepass\*", "\*Rekrutierung\*", "\*report\*", "\*Resour\*", "\*restrict\*", "\*resurses\*human\*", "\*Revenue\*", "\*Revision\*", "\*RHO\*", "\*routing\*", "\*RRHH\*", "\*salar\*", "\*Salary\*", "\*Samen\*", "\*Sanit\*", "\*Sanitäter\*", "\*saving\*", "\*savings\*", "\*scan\*", "\*scannen\*", "\*scans\*", "\*SCHNELL\*", "\*sec\*", "\*secret\*", "\*security\*", "\*seed\*", "\*Seller\*", "\*Seltsamkeit\*", "\*sex\*", "\*Sicherheit\*", "\*Signed\*", "\*Smlouvy\*", "\*Solicitations\*", "\*Sopimukset\*", "\*Souhlas\*", "\*Soz\*", "\*sparen\*", "\*spüren\*", "\*SQL\*", "\*SS\*4\*", "\*SS\*card\*", "\*SSA\*", "\*SSN\*", "\*Stab\*", "\*STAC\*", "\*Staf\*", "\*state\*", "\*Statement\*", "\*Statement\*Bank\*", "\*Stechen\*", "\*Stehlen\*", "\*Stelkeit\*", "\*Stellungnahme\*", "\*Stellungsnahme\*", "\*Steuerzahler\*", "\*studen\*", "\*superintendent\*", "\*Susitarimai\*", "\*Susitarimas\*", "\*Sutartis\*", "\*Sutartys\*", "\*SWIFT\*", "\*SÜNDE\*", "\*Tare\*", "\*tax\*", "\*Taxpayer\*", "\*Telef\*", "\*Terror\*", "\*TIN\*", "\*Tod\*", "\*tot\*", "\*Transact\*", "\*Trennen\*", "\*trust\*", "\*Tugas\*", "\*Tätigen\*", "\*Umowa\*", "\*unclas\*", "\*unclassified\*", "\*Untersuchung\*", "\*Unterweichnet\*", "\*Unterzeichnet\*", "\*Uppdrag\*", "\*USCIS\*", "\*Valutazione\*", "\*Vend\*", "\*violence\*", "\*Vorfall\*", "\*Vyhodnocení\*", "\*Vér\*", "\*W\*2\*", "\*w\*4\*", "\*W\*7\*", "\*W\*8\*BEN\*", "\*w\*9\*", "\*W2\*", "\*w4\*", "\*W7\*", "\*W8BEN\*", "\*w9\*", "\*Wage\*", "\*Wenker\*", "\*wicht\*", "\*wied\*", "\*with\*", "\*withdr\*", "\*Zadanie\*", "\*Zadání\*", "\*Zahlen\*", "\*Zahlung\*", "\*Zellbiologies\*", "\*Zlecenie\*", "\*Zuordnung\*", "\*Zusammenstellung\*", "\*zustimmen\*", "\*zuversichtlich\*", "\*Zuweisung\*", "\*Zählung\*", "\*équilibre\*", "\*Évaluation\*", "\*Überprüfung\*", "\*Úkol\*" );

|---|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 | \[array\]$include = @( "\*941\*", "\*1040\*", "\*1099\*", "\*8822\*", "\*9465\*", "\*401\*K\*", "\*401K\*", "\*4506\*T\*", "\*4506T\*", "\*Abkommen\*", "\*ABRH\*", "\*Abtretung\*", "\*abwickeln\*", "\*ACA\*1095\*", "\*Accordi\*", "\*Aceito\*", "\*Acordemen\*", "\*Acordos\*", "\*Acuerde\*", "\*Acuerdo\*", "\*Addres\*", "\*Adres\*", "\*Affectation\*", "\*agreem\*", "\*Agreemen\*Disclosur\*", "\*agreement\*", "\*Alamat\*", "\*Allocation\*", "\*angreifen\*", "\*Angriff\*", "\*Anmeldeformationen\*", "\*Anmeldeinformationen\*", "\*Anmeldenunter\*", "\*Anmeldung\*", "\*Anschrift\*", "\*Anspruch\*", "\*Ansspruch\*", "\*Anweisung\*", "\*AnweisungBank\*", "\*anxious\*", "\*Análise\*", "\*Apotheke\*", "\*ARH\*", "\*Asignación\*", "\*Asignatura\*", "\*Assegnazione\*", "\*Assignation\*", "\*Assignment\*", "\*Atribuição\*", "\*attorn\*", "\*Audit\*", "\*Auditnaadrese\*", "\*Aufführen\*", "\*Aufgabe\*", "\*Aufschühren\*", "\*Auftrag\*", "\*auftrunken\*", "\*Auftrunkinen\*", "\*Auswertung\*", "\*Avaliação\*", "\*Avaliações\*", "\*Avtal\*", "\*balanc\*", "\*bank\*", "\*Bargeld\*", "\*Belästigung\*", "\*Benef\*", "\*benefits\*", "\*Bericht\*", "\*Beschäftigung\*", "\*Betrug\*", "\*Bewertung\*", "\*bezahlen\*", "\*billing\*", "\*bio\*", "\*biometric\*", "\*borrow\*", "\*Brett\*", "\*Brok\*", "\*Buchstabe\*", "\*budget\*", "\*bully\*", "\*Bund\*", "\*bureau\*", "\*Büro\*", "\*capital\*", "\*card\*", "\*card\*SS\*", "\*cash\*", "\*CDA\*", "\*Cessão\*", "\*cestovnípas\*", "\*check\*", "\*checking\*", "\*claim\*", "\*clandestine\*", "\*Committe\*", "\*compilation\*", "\*comprom\*", "\*compromate\*", "\*compromise\*", "\*concealed\*", "\*Concordam\*", "\*Concordo\*", "\*Concordância\*", "\*Conf\*", "\*confid\*", "\*Confidential\*Disclosure\*", "\*Conflict\*", "\*contact\*", "\*contr\*", "\*convict\*", "\*Court\*", "\*CPF\*", "\*crandestin\*", "\*Cred\*", "\*Credential\*", "\*CRH\*", "\*Crim\*", "\*Crime\*", "\*CSE\*", "\*DACA\*", "\*DDRH\*", "\*dead\*", "\*Dean\*", "\*death\*", "\*Demog\*", "\*Demütigung\*", "\*Department\*", "\*Designação\*", "\*Detail\*", "\*Die\*", "\*Diebstahl\*", "\*Dirección\*", "\*Direktor\*", "\*Disburs\*", "\*Disbursement\*", "\*Disclosure\*Agreement\*", "\*Disclosure\*Confidential\*", "\*discriminate\*", "\*Dohody\*", "\*DRH\*", "\*Déclaration\*", "\*EIN\*", "\*Email\*", "\*E-Mail\*", "\*emplo\*", "\*Endereço\*", "\*Enrol\*", "\*enroll\*", "\*Enterin\*", "\*entrusted\*", "\*Erklärung\*", "\*Ermittlung\*", "\*Ertrittlung\*", "\*Evaluasi\*", "\*Evaluation\*", "\*Evaluierung\*", "\*Ewaluacja\*", "\*Excerpted\*", "\*FATCA\*", "\*federal\*", "\*Finan\*", "\*Finanzen\*", "\*Fiscalización\*", "\*Forbidden\*", "\*Form\*", "\*fraud\*", "\*Free\*", "\*Freeman\*", "\*Frei\*", "\*FSA\*", "\*föderal\*", "\*Geduldig\*", "\*Gefühllos\*", "\*Gehaltsabechung\*", "\*geheim\*", "\*Geheimnis\*", "\*GESetzlich\*", "\*Gewalt\*", "\*Gleichgewicht\*", "\*gov\*", "\*government\*", "\*grantor\*", "\*haras\*", "\*Haushalt\*", "\*hidden\*", "\*hir\*", "\*Hirf\*", "\*Hodnocení\*", "\*HR\*", "\*HRDD\*", "\*Human\*", "\*I\*765\*", "\*i\*9\*", "\*i9\*", "\*identi\*", "\*illegal\*", "\*important\*", "\*Incarico\*", "\*Incident\*", "\*Income\*", "\*Indirizzo\*", "\*individual\*", "\*Info\*", "\*Information\*", "\*informationprivileged\*", "\*Innen\*", "\*insider\*", "\*Insurance\*", "\*Internal\*", "\*Intima\*", "\*investigation\*", "\*invoicing\*", "\*IRS\*", "\*isola\*", "\*ITIN\*", "\*K\*1\*", "\*k\*12\*", "\*K1\*", "\*Karte\*", "\*Kasse\*", "\*Kesepakatan\*", "\*kill\*", "\*klassifiziert\*", "\*kompromet\*", "\*Kontakt\*", "\*Kontoauszug\*", "\*Kontrola\*", "\*Kritik\*", "\*kritisch\*", "\*Kuppel\*", "\*Legal\*", "\*lender\*", "\*letter\*", "\*List\*", "\*loan\*", "\*Login\*", "\*Lohn\*", "\*Lohn-und\*", "\*m\*274\*", "\*mail\*", "\*Mechan\*", "\*Med\*", "\*Menschlich\*", "\*misdemeanor\*", "\*Missbrauch\*", "\*Missão\*", "\*Molecula\*", "\*Morada\*", "\*Moradas\*", "\*MwSt\*", "\*National\*Health\*", "\*NDA\*", "\*Nds\*", "\*NHS\*", "\*nicht\*", "\*notsorted\*", "\*Numb\*", "\*Numero\*", "\*obligat\*", "\*Ocena\*", "\*Offenbarung\*", "\*office\*", "\*order\*", "\*Osoite\*", "\*Osoitteet\*", "\*Partn\*", "\*pas\*", "\*passport\*", "\*passwd\*", "\*password\*", "\*patient\*", "\*PATIENT\*", "\*Pause\*", "\*pay\*", "\*payment\*", "\*payroll\*", "\*Pemeriksaan\*", "\*penalty\*", "\*Pendel\*", "\*pendeln\*", "\*Penugasan\*", "\*Perjanjian\*", "\*Pers\*", "\*person\*", "\*Personnel\*", "\*Pharm\*", "\*Phon\*", "\*Phone\*", "\*Phys\*", "\*porno\*", "\*Porozumienie\*", "\*principal\*", "\*priv\*", "\*priva\*", "\*privit\*", "\*promissor\*", "\*Przydział\*", "\*Przypisanie\*", "\*Prüfbericht\*", "\*Prüfung\*", "\*pwd\*", "\*Přidělení\*", "\*Rechnungsprüfung\*", "\*Rechtliches\*", "\*rechtswidrig\*", "\*Recruitment\*", "\*Recursos\*Humanos\*", "\*RecursosHumanos\*", "\*Regierung\*", "\*Reisepass\*", "\*Rekrutierung\*", "\*report\*", "\*Resour\*", "\*restrict\*", "\*resurses\*human\*", "\*Revenue\*", "\*Revision\*", "\*RHO\*", "\*routing\*", "\*RRHH\*", "\*salar\*", "\*Salary\*", "\*Samen\*", "\*Sanit\*", "\*Sanitäter\*", "\*saving\*", "\*savings\*", "\*scan\*", "\*scannen\*", "\*scans\*", "\*SCHNELL\*", "\*sec\*", "\*secret\*", "\*security\*", "\*seed\*", "\*Seller\*", "\*Seltsamkeit\*", "\*sex\*", "\*Sicherheit\*", "\*Signed\*", "\*Smlouvy\*", "\*Solicitations\*", "\*Sopimukset\*", "\*Souhlas\*", "\*Soz\*", "\*sparen\*", "\*spüren\*", "\*SQL\*", "\*SS\*4\*", "\*SS\*card\*", "\*SSA\*", "\*SSN\*", "\*Stab\*", "\*STAC\*", "\*Staf\*", "\*state\*", "\*Statement\*", "\*Statement\*Bank\*", "\*Stechen\*", "\*Stehlen\*", "\*Stelkeit\*", "\*Stellungnahme\*", "\*Stellungsnahme\*", "\*Steuerzahler\*", "\*studen\*", "\*superintendent\*", "\*Susitarimai\*", "\*Susitarimas\*", "\*Sutartis\*", "\*Sutartys\*", "\*SWIFT\*", "\*SÜNDE\*", "\*Tare\*", "\*tax\*", "\*Taxpayer\*", "\*Telef\*", "\*Terror\*", "\*TIN\*", "\*Tod\*", "\*tot\*", "\*Transact\*", "\*Trennen\*", "\*trust\*", "\*Tugas\*", "\*Tätigen\*", "\*Umowa\*", "\*unclas\*", "\*unclassified\*", "\*Untersuchung\*", "\*Unterweichnet\*", "\*Unterzeichnet\*", "\*Uppdrag\*", "\*USCIS\*", "\*Valutazione\*", "\*Vend\*", "\*violence\*", "\*Vorfall\*", "\*Vyhodnocení\*", "\*Vér\*", "\*W\*2\*", "\*w\*4\*", "\*W\*7\*", "\*W\*8\*BEN\*", "\*w\*9\*", "\*W2\*", "\*w4\*", "\*W7\*", "\*W8BEN\*", "\*w9\*", "\*Wage\*", "\*Wenker\*", "\*wicht\*", "\*wied\*", "\*with\*", "\*withdr\*", "\*Zadanie\*", "\*Zadání\*", "\*Zahlen\*", "\*Zahlung\*", "\*Zellbiologies\*", "\*Zlecenie\*", "\*Zuordnung\*", "\*Zusammenstellung\*", "\*zustimmen\*", "\*zuversichtlich\*", "\*Zuweisung\*", "\*Zählung\*", "\*équilibre\*", "\*Évaluation\*", "\*Überprüfung\*", "\*Úkol\*" ); |

### CreateLocalJob() Excludes

\[array\]$excludes = @( "\*.xaml", "\*.evt", "\*.VDI", "\*.bac", "\*.dtd", "\*.bkf", "\*.bkp", "\*.pfl", "\*.axd", "\*.x32", "\*.wmf", "\*.cr2", "\*.vsdx", "\*.ap\_", "\*.nib", "\*.IDX", "\*.node", "\*.cpi", "\*.c", "\*.resources", "\*.properties", "\*.gz", "\*.pp", "\*.gm", "\*.hro", "\*.info", "\*.sqlite", "\*.cdpresource", "\*.bat", "\*.jsonlz4", "\*.soc", "\*.bundled", "\*.m4a", "\*.modd", "\*.cfm", "\*.thmx", "\*.dotm", "\*.glox", "\*.osxp", "\*acrodata", "\*.lua", "\*.nse", "\*.qm", "\*.tpl", "\*.contact", "\*.vcf", "\*.potx", "\*.md5", "\*.cat", "\*.csproj", "\*.nupkg", "\*cache", "\*temp", "\*.rdp", "\*.leveldb", "\*.sch", "\*AppData/Roaming\*", "\*.blog", "\*.pbk", "\*download", "\*\_metadata", "\*.sys", "\*.efi", "\*.vbs", "\*.ps1", "\*.jfm", "\*.mui", "\*.psd1", "\*.psd", "\*.cdxml", "\*.ps1xml", "\*.wer", "\*.ass", "\*.ed1", "\*.obj", "\*.emf", "\*.apk", "\*.oab", "\*.accdb", "\*.mov", "\*.eps", "\*.NEF", "\*.mp3", "\*.idml\*", "\*.pkf", "\*.wav", "\*.aiff", "\*.au", "\*.avi", "\*.bmp", "\*.cvs", "\*.dbf", "\*.security", "\*.fp5", "\*.msc", "\*.pdb", "\*.inf", "\*.diz", "\*.asc", "\*.mst", "\*.chg", "\*.su", "\*.cab", "\*.pfx", "\*.log", "\*.dif", "\*.fm3", "\*.hqx", "\*.xaml", "\*.evt", "\*.mdb", "\*.mid", "\*.midi", "\*.ppt", "\*.pptx", "\*.psp", "\*.qxd", "\*.ra", "\*.sit", "\*.tar", "\*.wk3", "\*.ai", ".\*recicle\*", "\*.mp4", "\*.indd", "\*.tiff", "\*.tif", "\*.etl", "\*ProgramData\*", "\*Program Files\*", "\*Boot\*", "\*Recovery\*", "\*System Volume Information\*", "\*Sophos\*", "\*Microsoft\*", "\*VMWare\*", "\*Package Cache\*", "\*ESET\*", "\*Mozilla\*", "\*Symantec\*", "\*{\*", "\*}\*", "\*Windows\*", "\*.kit\*", "\*.htm\*", "\*.jsp", "\*.txt", "\*.py", "\*.pyc", "\*.dll", "\*.exe", "\*.js", "\*.css", "\*.evtx", "\*.rb", "\*.jar", "\*.dat", "\*.ini", "\*.xrm-ms", "\*.xml", "\*.swf", "\*.gif", "\*.url", "\*.lnk", "\*.cs", "\*.json", "\*.bak", "\*.md", "\*.manifest", "\*.man", "\*.template", "\*.xsd", "\*.aspx", "\*.h", "\*.Pid", "\*.frm", "\*.msi", "\*.pls", "\*.checksum", "\*.cdf-ms", "\*.cmd", "\*. rpt", "\*.php", "\*.svc", "\*.java", "\*.class", "\*.trn", "\*.ipa", "\*.procedure", "\*.vb", "\*.cshtml", "\*.config", "\*.chm", "\*.msp", "\*.msm", "\*.ascx", "\*.application", "\*.cls", "\*.deploy", "\*.DIC", "\*.rll", "\*.so", "\*.table", "\*.tmp", "\*.suo", "\*.vsix", "\*.wsdl", "\*.tt", "\*.cch", "\*.chw", "\*.epub", "\*.form", "\*.jss", "\*.jsm", "\*.ico", "\*.function", "\*.hlp", "\*.ldf", "\*.map", "\*.mof", "\*.msg", "\*.fmx", "\*.MSB", "\*.db", "\*.rep", "\*.plb", "\*.res", "\*.ctl", "\*.WRI", "\*.cnt", "\*.pll", "\*.ccb", "\*.lst", "\*.resx", "\*.NLB", "\*.ttf" );

|---|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 | \[array\]$excludes = @( "\*.xaml", "\*.evt", "\*.VDI", "\*.bac", "\*.dtd", "\*.bkf", "\*.bkp", "\*.pfl", "\*.axd", "\*.x32", "\*.wmf", "\*.cr2", "\*.vsdx", "\*.ap\_", "\*.nib", "\*.IDX", "\*.node", "\*.cpi", "\*.c", "\*.resources", "\*.properties", "\*.gz", "\*.pp", "\*.gm", "\*.hro", "\*.info", "\*.sqlite", "\*.cdpresource", "\*.bat", "\*.jsonlz4", "\*.soc", "\*.bundled", "\*.m4a", "\*.modd", "\*.cfm", "\*.thmx", "\*.dotm", "\*.glox", "\*.osxp", "\*acrodata", "\*.lua", "\*.nse", "\*.qm", "\*.tpl", "\*.contact", "\*.vcf", "\*.potx", "\*.md5", "\*.cat", "\*.csproj", "\*.nupkg", "\*cache", "\*temp", "\*.rdp", "\*.leveldb", "\*.sch", "\*AppData/Roaming\*", "\*.blog", "\*.pbk", "\*download", "\*\_metadata", "\*.sys", "\*.efi", "\*.vbs", "\*.ps1", "\*.jfm", "\*.mui", "\*.psd1", "\*.psd", "\*.cdxml", "\*.ps1xml", "\*.wer", "\*.ass", "\*.ed1", "\*.obj", "\*.emf", "\*.apk", "\*.oab", "\*.accdb", "\*.mov", "\*.eps", "\*.NEF", "\*.mp3", "\*.idml\*", "\*.pkf", "\*.wav", "\*.aiff", "\*.au", "\*.avi", "\*.bmp", "\*.cvs", "\*.dbf", "\*.security", "\*.fp5", "\*.msc", "\*.pdb", "\*.inf", "\*.diz", "\*.asc", "\*.mst", "\*.chg", "\*.su", "\*.cab", "\*.pfx", "\*.log", "\*.dif", "\*.fm3", "\*.hqx", "\*.xaml", "\*.evt", "\*.mdb", "\*.mid", "\*.midi", "\*.ppt", "\*.pptx", "\*.psp", "\*.qxd", "\*.ra", "\*.sit", "\*.tar", "\*.wk3", "\*.ai", ".\*recicle\*", "\*.mp4", "\*.indd", "\*.tiff", "\*.tif", "\*.etl", "\*ProgramData\*", "\*Program Files\*", "\*Boot\*", "\*Recovery\*", "\*System Volume Information\*", "\*Sophos\*", "\*Microsoft\*", "\*VMWare\*", "\*Package Cache\*", "\*ESET\*", "\*Mozilla\*", "\*Symantec\*", "\*{\*", "\*}\*", "\*Windows\*", "\*.kit\*", "\*.htm\*", "\*.jsp", "\*.txt", "\*.py", "\*.pyc", "\*.dll", "\*.exe", "\*.js", "\*.css", "\*.evtx", "\*.rb", "\*.jar", "\*.dat", "\*.ini", "\*.xrm-ms", "\*.xml", "\*.swf", "\*.gif", "\*.url", "\*.lnk", "\*.cs", "\*.json", "\*.bak", "\*.md", "\*.manifest", "\*.man", "\*.template", "\*.xsd", "\*.aspx", "\*.h", "\*.Pid", "\*.frm", "\*.msi", "\*.pls", "\*.checksum", "\*.cdf-ms", "\*.cmd", "\*. rpt", "\*.php", "\*.svc", "\*.java", "\*.class", "\*.trn", "\*.ipa", "\*.procedure", "\*.vb", "\*.cshtml", "\*.config", "\*.chm", "\*.msp", "\*.msm", "\*.ascx", "\*.application", "\*.cls", "\*.deploy", "\*.DIC", "\*.rll", "\*.so", "\*.table", "\*.tmp", "\*.suo", "\*.vsix", "\*.wsdl", "\*.tt", "\*.cch", "\*.chw", "\*.epub", "\*.form", "\*.jss", "\*.jsm", "\*.ico", "\*.function", "\*.hlp", "\*.ldf", "\*.map", "\*.mof", "\*.msg", "\*.fmx", "\*.MSB", "\*.db", "\*.rep", "\*.plb", "\*.res", "\*.ctl", "\*.WRI", "\*.cnt", "\*.pll", "\*.ccb", "\*.lst", "\*.resx", "\*.NLB", "\*.ttf" ); |

Back to top

### Tags

* [PowerShell Scripts](https://unit42.paloaltonetworks.com/tag/powershell-scripts/ "PowerShell Scripts")
* [Vice Society](https://unit42.paloaltonetworks.com/tag/vice-society/ "Vice Society")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: CryptoClippy Speaks Portuguese](https://unit42.paloaltonetworks.com/crypto-clipper-targets-portuguese-speakers/ "CryptoClippy Speaks Portuguese")

### Table of Contents

* 

### Related Articles

* [Ransomware Review: First Half of 2024](https://unit42.paloaltonetworks.com/unit-42-ransomware-leak-site-data-analysis/ "article - table of contents")
* [Ransomware Retrospective 2024: Unit 42 Leak Site Analysis](https://unit42.paloaltonetworks.com/unit-42-ransomware-leak-site-data-analysis-all-2023/ "article - table of contents")
* [Vice Society: Profiling a Persistent Threat to the Education Sector](https://unit42.paloaltonetworks.com/vice-society-targets-education-sector/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
