Is 360.CN Evil?
ID: bf83cba4-4490-5d62-8f37-cc33303ee2bf
STIX ID: report--bf83cba4-4490-5d62-8f37-cc33303ee2bf
Feed Name: Zscaler Security Research Blog
Threat Score
The report raises concerns that Qihoo's 360.cn security suite performs frequent HTTP POST beaconing to conf.f.360.cn and qurl.f.360.cn (User-Agent "Post_Multipart", ~1200 bytes sent, 164 bytes returned), notes McAfee and VirusTotal detections flagging the software or associated binaries as spyware, and recommends monitoring or blocking the domains while further packet captures are obtained to determine if user data is being exfiltrated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
