[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-ursnif-infections/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/wireshark-tutorial-examining-ursnif-infections/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/ "Learning Hub")
* [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/ "Cybersecurity Tutorials")  
  [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)

# Wireshark Tutorial: Examining Ursnif Infections

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 14 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Brad Duncan](https://unit42.paloaltonetworks.com/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:December 23, 2019

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)
  * [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/)
  * [Ursnif](https://unit42.paloaltonetworks.com/tag/ursnif/)
  * [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/)
  * [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-ursnif-infections/?pdf=download&lg=en&_wpnonce=0070e94fe3 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-ursnif-infections/?pdf=print&lg=en&_wpnonce=0070e94fe3 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Wireshark%20Tutorial:%20Examining%20Ursnif%20Infections&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-examining-ursnif-infections%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-examining-ursnif-infections%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-examining-ursnif-infections%2F&title=Wireshark%20Tutorial:%20Examining%20Ursnif%20Infections "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-examining-ursnif-infections%2F&text=Wireshark%20Tutorial:%20Examining%20Ursnif%20Infections "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-examining-ursnif-infections%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Wireshark%20Tutorial:%20Examining%20Ursnif%20Infections%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-examining-ursnif-infections%2F "Share in Mastodon")
  [Ursnif](https://attack.mitre.org/software/S0386/) is banking malware sometimes referred to as Gozi or IFSB. The Ursnif family of malware has been active for years, and current samples generate distinct traffic patterns.

This tutorial reviews packet captures (pcaps) of infection Ursnif traffic using [Wireshark](https://www.wireshark.org). Understanding these traffic patterns can be critical for security professionals when detecting and investigating Ursnif infections.

This tutorial covers the following:

* Ursnif distribution methods
* Categories of Ursnif traffic
* Five examples of pcaps from Ursnif infections

Note: This tutorial assumes you have a basic knowledge of Wireshark, and it uses a customized column display shown in [this tutorial](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/). You should also have experience with Wireshark display filters as described in [this additional tutorial](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/).

## Ursnif Distribution Methods

Ursnif can be distributed through web-based infection chains and malicious spam (malspam). In some cases, Ursnif is a follow-up infection caused by different malware families like [Hancitor](https://unit42.paloaltonetworks.com/unit42-compromised-servers-fraud-accounts-recent-hancitor-attacks/), as reported in [this recent example](https://isc.sans.edu/forums/diary/Hancitor+infection+with+Pony+Evil+Pony+Ursnif+and+Cobalt+Strike/25532/).

We frequently find examples of Ursnif from malspam-based distribution campaigns, such as the example in Figure 1.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-42.jpeg)*Figure 1. Flowchart from one of the more common Ursnif distribution campaigns.*

## Categories of Ursnif Traffic

This tutorial covers two categories of Ursnif infection traffic:

* Ursnif without HTTPS post-infection traffic
* Ursnif with HTTPS post-infection traffic

Malware samples from either of these categories create the same type of artifacts on an infected Windows host. For example, both types of Ursnif remain persistent on a Windows host by updating the Windows registry, such as the example shown in Figure 2.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-43.jpeg)*Figure 2. Example of Windows registry updates caused by samples of Ursnif, either with or without HTTPS post-infection traffic.*

## Example 1: Ursnif without HTTPS

The first pcap for this tutorial, ***Ursnif-traffic-example-1.pcap*** , is available [here](https://www.malware-traffic-analysis.net/training/examining-ursnif.html). The chain of events behind this traffic was tweeted [here](https://twitter.com/malware_traffic/status/1203071348941246464). Example 1 has been stripped of all traffic not directly related to the Ursnif infection.

Open the pcap in Wireshark and filter on ***http.request*** as shown in Figure 3.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-44.jpeg)*Figure 3. The pcap for example 1 filtered in Wireshark.*

In this example, the Ursnif-infected host generates post-infection traffic to 8.208.24\[.\]139 using various domain names ending with .at. This category of Ursnif causes the following traffic:

* HTTP GET requests caused by the initial Ursnif binary
* HTTP GET request for follow-up data, with the URL ending in .dat
* HTTP GET and POST requests after Ursnif is persistent in the Windows registry

The following HTTP data is used during the traffic in our first example:

* Domain for initial GET requests: w8.wensa\[.\]at
* Request for follow-up data: hxxp://api2.casys\[.\]at/jvassets/xI/t64.dat
* Domain for GET and POST requests after Ursnif is persistent: h1.wensa\[.\]at

Follow the TCP stream for the very first HTTP GET request at 20:13:09 UTC. The TCP stream window shows the full URL. Note how the GET request starts with /api1/ and is followed by a long string of alpha-numeric characters with backslashes and underscores. Figure 4 highlights the GET request.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-45.jpeg)*Figure 4. Example of an HTTP GET request caused by our first Ursnif example.*

We can find the same pattern from Ursnif activity caused by a Hancitor infection on December 10,2019. The pcap is available [here](https://www.malware-traffic-analysis.net/2019/12/10/index.html). Mixed with the other malware activity, this December 10th example contains the following indicators for Ursnif:

* Domain for initial GET requests: foo.fulldin\[.\]at
* Request for follow-up data: hxxp://one.ahah100\[.\]at/jvassets/o1/s64.dat
* Domain for GET and POST requests after Ursnif is persistent: api.ahah100\[.\]at

Note how patterns from Ursnif traffic in the December 10th example are similar to the patterns we find in example 1. These patterns are commonly seen from Ursnif samples that do not use HTTPS traffic.

## Example 2: Ursnif with HTTPS

The second pcap for this tutorial, ***Ursnif-traffic-example-2.pcap*** , is available [here](https://www.malware-traffic-analysis.net/training/examining-ursnif.html). Like our first pcap, this one has also been stripped of any traffic not related to the Ursnif infection.

Open the pcap in Wireshark and filter on ***http.request or ssl.handshake.type == 1*** as shown in Figure 5. If you are using Wireshark 3.0 or newer, filter on ***http.request or tls.handshake.type == 1*** for the correct results.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-46.jpeg)*Figure 5. The pcap for our second example filtered in Wireshark.*

This example has the following sequence of events:

* HTTP GET request that returns an initial Ursnif binary
* HTTP GET requests caused by the initial Ursnif binary
* HTTPS traffic after Ursnif is persistent in the Windows registry

Follow the TCP stream for the first HTTP GET request to ghinatronx\[.\]com. This TCP stream reveals a Windows executable or DLL file as shown in Figure 6. We can export the Ursnif binary from the pcap as described in[this previous tutorial](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/).

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-47.jpeg)*Figure 6. The first HTTP GET request returning a binary for Ursnif.*

The next four HTTP requests to bjanicki\[.\]com were caused by the Ursnif binary. Follow the TCP stream for the first HTTP GET request to bjanicki\[.\]com at 18:46:21 UTC. This TCP stream shows the full URL. Note how the GET request starts with /images/ and is followed by a long string of alpha-numeric characters with backslashes and underscores before ending with .avi. This URL pattern is somewhat similar to Ursnif traffic from our first pcap. Figure 7 highlights a GET request from our second pcap.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-48.jpeg)*Figure 7. Example of an HTTP GET request from our second Ursnif example.*

Unlike our first example, Ursnif in this second pcap generates HTTPS traffic after it becomes persistent on an infected Windows host. Use your ***basic*** web filter as described in[this previous tutorial](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/) for a quick review of the HTTPS traffic. Note the HTTPS traffic to prodrigo29lbkf20\[.\]com as shown in Figure 8.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-49.jpeg)*Figure 8. Filtering on web traffic in Wireshark, highlighting the HTTPS traffic generated by Ursnif.*

HTTPS traffic generated by this Ursnif variant reveals distinct characteristics in certificates used to establish encrypted communications. To get a closer look, filter on***ssl.handshake.type == 11*** (or ***tls.handshake.type == 11*** in Wireshark 3.0 or newer). Select the first frame in the results and go to the frame details window. There we can expand lines and work our way to the certificate issuer data. Figure 9 shows how to begin.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-50.jpeg)*Figure 9. Finding our way to the certificate issuer data.*

As shown in Figure 9, we expand the line for ***Secure Sockets Layer*** in the frame details window. For Wireshark 3.0, this line shows as ***Transport Layer Security*** . Then we expand the line labeled ***TLSv1.2 Record Layer: Handshake Protocol: Certificate*** . Then we expand the line labeled ***Handshake Protocol: Certificate***.

We keep expanding, until we find our way to the certificate issuer data as shown in Figure 10.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-51.jpeg)*Figure 10. Certificate issuer data from HTTPS traffic caused by Ursnif.*

In Figure 10 shown under the ***Handshake Protocol: Certificate*** line, we work our way down through the following items:

* Certificates (615 bytes)
* Certificate: 30820260308201c9a003020102020900c692c94106d77dfc...
* signedCertificate
* Issuer: rdnSequence (6)
* rdnSequence: 6 items (id-at-commonName=\*,id-at-organizationalUnitN...

Individual items under the ***rdnSequence*** line show properties of the certificate issuer. These reveal the following characteristics:

* countryName=**XX**
* stateOrProvinceName=**1**
* localityName=**1**
* organizationName=**1**
* organizationalUnitName=**1**
* commonName=**\***

This issuer data is not valid, and these patterns are commonly seen in Ursnif infections. But what does legitimate certificate data look like? Figure 11 shows valid data from a certificate issued by DigiCert.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-52.jpeg)*Figure 11. Valid certificate issuer data.*

One last thing about Ursnif is the IP address check by an Ursnif-infected host. This happens over DNS using a resolver at opendns\[.\]com. Like other IP address identifiers, this is a legitimate service. However, these services are commonly used by malware.

To see this IP address check, filter on ***dns.qry.name contains opendns.com*** and review the results as shown in Figure 12.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-53.jpeg)*Figure 12. IP address check by an Ursnif-infected Windows host.*

As shown in Figure 12, the Window host generated a dns query for resolver1.opendns\[.\]com followed by a DNS query to 208.67.222\[.\]222 for myip.opendns\[.\]com. The DNS query to myip.opendns\[.\]com returned the public IP address of the infected Windows host.

## Example 3: Ursnif with Follow-up Malware

Our third pcap, ***Ursnif-traffic-example-3.pcap*** , is available [here](https://www.malware-traffic-analysis.net/training/examining-ursnif.html). This pcap also has unrelated activity stripped from the traffic, but it builds on our last example. Our third pcap includes what appears to be decoy traffic, and it also includes an HTTP GET request for follow-up malware. The sequence of events is:

* HTTP GET request that returns an initial Ursnif binary
* HTTP GET requests caused by the initial Ursnif binary, including decoy URLs
* HTTPS traffic after Ursnif is persistent in the Windows registry
* HTTP GET request for follow-up malware

Use your ***basic*** web filter as described in[this previous tutorial](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/) for a quick review of the web-based traffic as shown in Figure 13.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-54.jpeg)Figure 13. Filtering our third pcap for web traffic in Wireshark.*

In Figure 13, the initial HTTP request to sinicaleer\[.\]com returned a Windows executable for Ursnif. The remaining traffic visible Figure 13 was caused by the Ursnif executable until it became persistent.

Three HTTP requests to google\[.\]com follow similar URL patterns as Ursnif traffic to an actual malicious domain of ghdy656262oe\[.\]com. These HTTP GET requests to google\[.\]com appear to be decoy traffic, because they do not assist the infection. HTTPS traffic over TCP port 443 to gmail\[.\]com and www.google\[.\]com also serves no direct purpose for the infection, and that activity could also be classified as decoy traffic. Figure 14 shows an example of the decoy HTTP GET requests to google\[.\]com.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-55.jpeg)Figure 14. Decoy HTTP GET request by the Ursnif-infected host to a Google domain.*

Note the HTTP traffic to ghdy656262oe\[.\]com. The first two GET requests to ghdy656262oe\[.\]com return a ***404 Not Found*** response as shown in Figure 15. The third HTTP GET request returns a ***200 OK*** response, and the infection continues as shown in Figure 16.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-56.jpeg)*Figure 15. First two HTTP GET requests to malicious Ursnif domain return a 404 Not Found response.*

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-57.jpeg)Figure 16. Some false starts before the Ursnif infection continues.*

Since the first HTTP GET request to ghdy656262oe\[.\]com was not a 200 OK, the infected Windows host cycled through other malicious domains to continue the infection. These two domains are tnzf3380au\[.\]top and xijamaalj\[.\]com. However, the DNS queries for these domains returned a "No such name" in response, so the infected Windows host went back to trying ghdy656262oe\[.\]com.

Use the following Wireshark filter to better see this sequence of events:

***((http.request or http.response) and ip.addr eq 194.1.236.191) or dns.qry.name contains tnzf3380au or dns.qry.name contains xijamaalj***

The results should appear similar to the column display in Figure 17.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-58.jpeg)*Figure 17. Filtering to show how the infected Windows host tries Ursnif-related domains before it hits a 200 OK in HTTP traffic.*

To review the rest of the infection, use your ***basic*** web filter and scroll to the end of the results. Figure 18 shows the post-infection traffic after Ursnif becomes persistent.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-59.jpeg)*Figure 18. Post-infection traffic after Ursnif becomes persistent on the victim's Windows host.*

In Figure 18, after five HTTP GET requests to ghdy656262oe\[.\]com, we find traffic generated by the infected Windows host after Ursnif becomes persistent. This includes HTTPS traffic to google\[.\]com and gmail\[.\]com.

Traffic to vnt69tnjacynthe\[.\]com should have the same type of certificate issuer data we witnessed in our second pcap. But this traffic includes an HTTP GET request to carresqautomotive\[.\]com ending with .rar.

This URL ending in .rar returned follow-up malware. However, this follow-up malware is encoded or otherwise encrypted when sent over the network. The binary decoded on the infected Windows host, which is not seen in the infection traffic. Follow the TCP stream for the HTTP GET request to carresqautomotive\[.\]com, and you should see the same data as shown in Figure 19.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-60.jpeg)*Figure 19. Follow-up malware sent to an Ursnif-infected Windows host.*

This data is encrypted, so we cannot export a copy of the follow-up malware from the pcap. Therefore, we must rely on other post-infection traffic to determine what type of malware was sent to the Ursnif-infected host.

We have seen various types of follow-up malware from Ursnif infections, including [Dridex](https://www.malware-traffic-analysis.net/2019/12/02/index.html), [IcedID](https://www.malware-traffic-analysis.net/2019/10/21/index.html), [Nymain](https://www.malware-traffic-analysis.net/2019/05/03/index.html), [Pushdo](https://www.malware-traffic-analysis.net/2019/07/29/index.html), and [Trickbot](https://www.malware-traffic-analysis.net/2019/09/04/index.html).

Our next example is an Ursnif infection with Dridex as the follow-up malware.

## Example 4: Ursnif Infection with Dridex

Our fourth pcap, ***Ursnif-traffic-example-4.pcap*** , is available [here](https://www.malware-traffic-analysis.net/training/examining-ursnif.html). Unlike our first three examples, this pcap does not have unrelated activity stripped from the traffic.

Use your ***basic*** web filter to get a better idea of the traffic. Your results should appear similar to Figure 20.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-61.jpeg)Figure 20. Traffic from our fourth pcap filtered in Wireshark.*

This pcap has the same sequence of events as our previous example, but it adds post-infection activity from the follow-up malware:

* HTTP GET request that returns an initial Ursnif binary
* HTTP GET requests caused by the initial Ursnif binary, including decoy URLs
* HTTPS traffic after Ursnif is persistent in the Windows registry
* HTTP GET request for follow-up malware
* Post-infection activity from the follow-up malware

In this fourth example, the HTTP GET request for an initial Ursnif binary is to oklogallem\[.\]com. Ursnif causes HTTP GET requests to kh2714ldb\[.\]com before the infection becomes persistent.

Figure 21 shows activity after Ursnif is persistent, where Ursnif causes HTTPS traffic to s9971kbjjessie\[.\]com. We then see an HTTP GET request to startuptshirt\[.\]my for the follow-up malware. Finally we find post-infection traffic caused by the follow-up malware.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-62.jpeg)Figure 21. Activity from the infection after Ursnif is persistent.*

Our fourth example follows the same infection patterns as our third pcap, but now we also have HTTPS/SSL/TLS traffic to 94.140.114\[.\]6 and 5.61.34\[.\]51 without any associated domain name. This is Dridex post-infection traffic.

Certificate issuer data for Dridex is different than certificate issuer data for Ursnif. Use the following filter to review the Dridex certificate data in our fourth pcap:

***(ip.addr eq 94.140.114.6 or ip.addr eq 5.61.34.51) and ssl.handshake.type eq 11***

Note: if you are using Wireshark 3.0 or newer, use ***tls.handshake.type*** instead of ***ssl.handshake.type***.

Select the first frame in the results, go to the frame details window, and expand the certificate-related lines as shown by our second example in Figures 9 and 10. Examining certificate issuer data from our fourth pcap should look similar to Figures 22 and 23.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-63.jpeg)*Figure 22. Working our way to the certificate issuer data in the Dridex traffic.*

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-64.jpeg)Figure 23. Reaching the certificate issuer data from one of the Dridex IP addresses.*

Under the ***rdnSequence*** line, we find properties of the certificate issuer. Certificate issuer characteristics for HTTPS/SSL/TLS traffic at 94.140.114\[.\]6 follows:

* countryName=**NP**
* localityName=**Kathmandu**
* organizationName=**Buvecoww Fftaites O.V.E.E.**
* organizationalUnitName=**Olfo Dusar Latha**
* commonName=**ndltman-dsamutb.spiegel**

Certificate issuer data is different for 5.61.34\[.\]51, but it follows a similar style:

* countryName=**MU**
* localityName=**Port Louis**
* organizationName=**Ppoffi Sourinop Cooperative**
* organizationalUnitName=**ipeepstha and thicioi**
* commonName=**plledsaprell.Byargt9wailen.voting**

This type of issuer data is commonly seen for Dridex post-infection traffic. In our next example, you can further practice reviewing certificate issuer data for Dridex.

## Example 5: Evaluation

The fifth pcap for this tutorial, ***Ursnif-traffic-example-5.pcap*** , is available [here](https://www.malware-traffic-analysis.net/training/examining-ursnif.html). Like our previous example, this pcap has an Ursnif infection followed by Dridex, so we can practice the skills described so far in this tutorial.

Based on what we have learned so far, open the fifth pcap in Wireshark, and answer the following questions:

* For the initial Ursnif binary, which URL returned a Windows executable file?
* After the initial Ursnif binary was sent, the infected Windows host contacted different domains for the HTTP GET requests. Which domain was the traffic successful and allowed the infection to proceed?
* What domain was used in HTTPS traffic after Ursnif became persistent on the infected Windows host?
* What URL ending in .rar was used to send follow-up malware to the infected Windows host?
* What IP addresses were used for the Dridex post-infection traffic?

Answers follow.

**Q:** For the initial Ursnif binary, which URL returned a Windows executable file?

**A:** hxxp://ritalislum\[.\]com/obedle/zarref.php?l=sopopf8.cab

The only Windows executable file in this pcap is the initial Windows executable file for Ursnif. Use the following Wireshark search filter to quickly find this executable:

***ip contains "This program"***

This filter should provide only one frame in the results. Follow the TCP stream for this frame as shown in Figure 24.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-65.jpeg)Figure 24. Filtering to find a frame with the Windows executable file and following the TCP stream.*

The TCP stream window contains the domain and URL from the GET request as shown in Figure 25.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-66.jpeg)Figure 25. URL info from the TCP stream.*

\*\*Q:\*\*After the initial Ursnif binary was sent, the infected Windows host contacted different domains for the HTTP GET requests. Which domain was the traffic successful and allowed the infection to proceed?

**A:** k55gaisi\[.\]com

Use your ***basic*** web filter for an overview of the web traffic. HTTP requests caused by this variant of Ursnif start with GET /images/ as already seen in examples two, three, and four of this tutorial. The first HTTP request to k55gaisi\[.\]com at 15:36 UTC is noted in Figure 26. But if you follow the TCP stream, it shows a 404 Not Found as the response.

![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-67.jpeg)*Figure 26. Searching web traffic for HTTP GET requests caused by Ursnif.*

Also shown in Figure 26, the next HTTP GET request for an Ursnif-style URL is to bon11ljgarry\[.\]com at 15:37 UTC. The HTTP stream for that request reveals a redirect to a URL at www.search-error\[.\]com.

Scroll down further, and for similar traffic to leinwqoa\[.\]com as noted in Figure 27.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-68.jpeg)Figure 27. Finding another Ursnif-style URL that redirects to a search error page.*

Scroll down further to find four HTTP GET requests to k55gaisi\[.\]com that return 200 OK responses. From this point, the Ursnif infection proceeds, and we find no further Ursnif-style HTTP requests that start with GET /images/.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-69.jpeg)Figure 28. Finding the Ursnif-style HTTP GET requests that return a 200 OK.*

**Q:** What domain was used in HTTPS traffic after Ursnif became persistent on the infected Windows host?

**A:** n9maryjanef\[.\]com

When Ursnif is persistent, we no longer see Ursnif-style HTTP requests starting with GET /images/. Instead, we find Ursnif-related HTTPS traffic. Shortly after the final Ursnif-style HTTP GET request, HTTPS traffic to n9maryjanef\[.\]com begins on 185.118.165\[.\]109 as highlighted in Figure 29. This is Ursnif traffic.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-70.jpeg)Figure 29. HTTPS traffic caused by Ursnif.*

You can confirm this is Ursnif traffic by filtering on ***ip.addr eq 185.118.165.109 and ssl.handshake.type == 11*** and reviewing the certificate issuer data. The certificate issuer data should look the same as our second example in Figure 10.

**Q:** What URL ending in .rar was used to send follow-up malware to the infected Windows host?

**A:** hxxps://testedsolutionbe\[.\]com/wp-content/plugins/apikey/uaasdqweeeeqsd.rar

HTTP GET requests caused by Ursnif for follow-up malware end in .rar, so use the following filter to find this URL in our pcap:

***http.request and ip contains .rar***

The results should be similar to what we see in Figure 30.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-71.jpeg)Figure 30. Finding the URL for follow-up malware from this Ursnif infection.*

Notice in Figure 30 how the HTTP GET request in Figure 30 redirects to an HTTPS URL.

**Q:** What IP addresses were used for the Dridex post-infection traffic?

**A:** 185.99.133\[.\]38 and 5.61.34\[.\]51

One of these IP addresses is the same as Dridex in our fourth pcap, and it has the same certificate issuer data. Dridex traffic to 185.99.133\[.\]38 has the same style of certificate issuer data as seen in example 4. Traffic to both IP addresses does not involve a domain name.

The Dridex post-infection traffic is easy to spot in this example if we look for any HTTPS/SSL/TLS traffic without a domain after the HTTP GET request ending in .rar as shown in Figure 31.

*![](https://unit42.paloaltonetworks.com/wp-content/uploads/2019/12/word-image-72.jpeg)Figure 31. Finding the Dridex traffic in our fifth pcap.*

## Conclusion

This tutorial provided tips for examining Windows infections with Ursnif malware. More pcaps with examples of Ursnif activity can be found at [malware-traffic-analysis.net](https://www.malware-traffic-analysis.net).

For more help with Wireshark, see our previous tutorials:

* * [Customizing Wireshark -- Changing Your Column Display](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/)
  * [Using Wireshark -- Display Filter Expressions](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/)
  * [Using Wireshark: Identifying Hosts and Users](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/)
  * [Using Wireshark: Exporting Objects from a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/)
  * [Wireshark Tutorial: Examining Trickbot Infections](https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-trickbot-infections/)
    Back to top

### Tags

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")
* [Ursnif](https://unit42.paloaltonetworks.com/tag/ursnif/ "Ursnif")
* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")
* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Unit 42 Discovers 13 New Vulnerabilities Across Microsoft and Adobe Products](https://unit42.paloaltonetworks.com/unit-42-discovers-13-new-vulnerabilities-across-microsoft-and-adobe-products/ "Unit 42 Discovers 13 New Vulnerabilities Across Microsoft and Adobe Products")

### Table of Contents

* 

### Related Articles

* [Wireshark Tutorial: Exporting Objects From a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/ "article - table of contents")
* [From DarkGate to AsyncRAT: Malware Detected and Shared As Unit 42 Timely Threat Intelligence](https://unit42.paloaltonetworks.com/unit42-threat-intelligence-roundup/ "article - table of contents")
* [Wireshark Tutorial: Identifying Hosts and Users](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/ "article - table of contents")

## Related Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
