{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Kimwolf v7 represents a significant jump in botnet resilience using blockchain infrastructure. A negative hunt result confirms that internal IoT assets are not participating in global DDoS campaigns or resolving C2 via Ethereum Name Service gateways."
      },
      "name": "Kimwolf Blockchain C2 and DDoS Impact",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1102.003",
        "attack.t1090",
        "attack.t1498.001"
      ],
      "series": {
        "slug": "kimwolf-v7-an-evolution-of-the-kimwolf-botnet",
        "index": 2,
        "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
        "total": 2
      },
      "related": [
        {
          "hunt": "kimwolf-initial-access-adb",
          "reason": "Propagation via unauthenticated ADB on port 5555 is a distinct initial access pattern handled by a separate infection-focused hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "kimwolf-adb-propagation-evasion",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standard detection rule might alert on a single C2 IP, but this hunt correlates the modular internal proxy routing (port 23075), the rare use of Ethereum RPC services for domain resolution on IoT hosts, and the resulting high-cardinality outbound traffic spikes. This multi-stage correlation captures a functional bot presence that simple indicator matches miss.",
      "coverage": [
        {
          "stage": "c2-ens-resolution",
          "steps": [
            "ens-rpc-dns-resolution"
          ],
          "status": "covered"
        },
        {
          "stage": "c2-local-proxy-routing",
          "steps": [
            "local-proxy-listener"
          ],
          "status": "covered"
        },
        {
          "stage": "impact-ddos-flooding",
          "steps": [
            "kimwolf-c2-outbound-floods"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-adb-misuse",
          "reason": "Belongs to another part of the 'Kimwolf v7: An Evolution of the Kimwolf Botnet' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-malware-installation",
          "reason": "Belongs to another part of the 'Kimwolf v7: An Evolution of the Kimwolf Botnet' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "defense-evasion-process-masquerading",
          "reason": "Belongs to another part of the 'Kimwolf v7: An Evolution of the Kimwolf Botnet' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Unauthenticated ADB Access",
            "slug": "initial-access-adb-misuse",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Inbound connections to TCP port 5555 (Android Debug Bridge)",
              "Use of residential proxy services to tunnel into local networks"
            ]
          },
          {
            "name": "Malware Installation via ADB",
            "slug": "execution-malware-installation",
            "tactic": "execution",
            "techniques": [
              "T1059"
            ],
            "observables": [
              "Installation of ELF binaries on Android devices",
              "Dropped files named libdevice.so or libn[redacted]kernel.so"
            ]
          },
          {
            "name": "Process Name Masquerading",
            "slug": "defense-evasion-process-masquerading",
            "tactic": "defense-evasion",
            "techniques": [
              "T1036.005"
            ],
            "observables": [
              "Process name masked as netd_service",
              "Stripped ELF binaries compiled with Android NDK",
              "Creation of Unix domain socket beginning with @n[redacted]boxv7"
            ]
          },
          {
            "name": "ENS C2 Resolution",
            "slug": "c2-ens-resolution",
            "tactic": "command-and-control",
            "techniques": [
              "T1102.003"
            ],
            "observables": [
              "Outbound traffic to 0xrpc.io",
              "Outbound traffic to eth.llamarpc.com",
              "Outbound traffic to ethereum-rpc.publicnode.com",
              "Outbound traffic to eth-protect.rpc.blxrbdn.com",
              "Outbound traffic to eth.merkle.io",
              "Outbound traffic to eth.rpcuniverse.com",
              "DNS queries for ENS C2 domains"
            ]
          },
          {
            "name": "Local Proxy Architecture",
            "slug": "c2-local-proxy-routing",
            "tactic": "command-and-control",
            "techniques": [
              "T1090"
            ],
            "observables": [
              "Local network listener on 127.0.0.1:23075",
              "Connections to v3 Tor .onion address: edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd.onion",
              "Direct C2 connections to 212.193.31.119, 212.193.31.122 (port 13)",
              "Direct C2 connections to 212.193.31.92, 212.193.31.158 (port 443)"
            ]
          },
          {
            "name": "DDoS Flood Activities",
            "slug": "impact-ddos-flooding",
            "tactic": "impact",
            "techniques": [
              "T1498.001"
            ],
            "observables": [
              "HTTP/2 floods with Chrome browser fingerprints",
              "High-performance UDP floods using ARM NEON SIMD optimizations",
              "TCP SYN, ACK, and RST floods",
              "DNS query floods",
              "ICMP floods"
            ]
          }
        ],
        "summary": "Kimwolf v7 is an evolution of an Android IoT botnet that targets unauthenticated ADB interfaces on port 5555 for initial access. The malware employs highly resilient command-and-control infrastructure using Ethereum Name Service (ENS) for resolution and Tor as a backup, ultimately performing optimized DDoS floods including stealthy HTTP/2 browser fingerprinting."
      },
      "severity": "high",
      "rationale": "Target Android TV boxes, set-top boxes, and Linux-based IoT segments. These devices are the primary beachhead for Kimwolf v7 and are less likely to perform legitimate Ethereum RPC queries.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "IoT or Android devices in the environment are infected with Kimwolf v7, as indicated by a local proxy listener on port 23075 and Ethereum Name Service (ENS) resolution used to bypass traditional C2 infrastructure takedowns.",
      "parameters": {
        "c2_ips": {
          "from": {
            "ref": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
            "kind": "article",
            "observed": "2026-08-11"
          },
          "type": "list[ip]",
          "default": [
            "212.193.31.119",
            "212.193.31.122",
            "212.193.31.92",
            "212.193.31.158",
            "212.193.31.102"
          ],
          "description": "Known Kimwolf C2 IP addresses residing in AS202799."
        },
        "c2_domains": {
          "from": {
            "ref": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
            "kind": "article",
            "observed": "2026-08-11"
          },
          "type": "list[domain]",
          "default": [
            "0xrpc.io",
            "eth.llamarpc.com",
            "ethereum-rpc.publicnode.com",
            "eth-protect.rpc.blxrbdn.com",
            "eth.merkle.io",
            "eth.rpcuniverse.com",
            "rpcuniverse.com"
          ],
          "description": "Ethereum RPC endpoints and ENS gateways used by Kimwolf for C2 resolution."
        },
        "proxy_port": {
          "type": "number",
          "default": "23075",
          "description": "The hard-coded local proxy port used by Kimwolf v7 for routing C2 traffic."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hosts to scope the hunt; leave empty to hunt across the entire estate."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "name": "Unit 42 \u2014 Kimwolf v7: An Evolution of the Kimwolf Botnet"
        }
      ],
      "blind_spots": [
        {
          "id": "tor-backup-blind-spot",
          "risk": "If ENS resolution fails, the botnet reverts to Tor routing via a local proxy; standard DNS monitoring will not see this fallback activity.",
          "stage": "c2-local-proxy-routing",
          "question": "Is the malware actively using the hard-coded Tor .onion backup for C2 communication?",
          "requires": "Network flow logs with SNI or full proxy inspection"
        },
        {
          "id": "http2-fingerprint-visibility",
          "risk": "While high connection counts are visible, the stealthy HTTP/2 browser fingerprinting may blend into normal traffic if the environment has high baseline web usage.",
          "stage": "impact-ddos-flooding",
          "question": "Does the DDoS traffic exactly match the Chrome fingerprints reported in the research?",
          "requires": "hb_http_activity with nghttp2 specific header metadata"
        }
      ]
    },
    "name": "Kimwolf Blockchain C2 and DDoS Impact",
    "description": "This hunt identifies Kimwolf v7 activity by correlating its unique local proxy architecture with blockchain-based C2 resolution and outbound DDoS flood behavior. Kimwolf v7 uses Ethereum public RPC endpoints to resolve ENS domains for its primary C2, ensuring resilience against domain seizures. The hunt searches for the local proxy listener that routes bot traffic, validates queries to known Ethereum RPC services, and identifies anomalous outbound traffic volumes consistent with the botnet's 15 distinct DDoS methods."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "kimwolf-v7-an-evolution-of-the-kimwolf-botnet",
          "index": 2,
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "total": 2
        },
        "coverage": [
          {
            "stage": "c2-ens-resolution",
            "steps": [
              "ens-rpc-dns-resolution"
            ],
            "status": "covered"
          },
          {
            "stage": "c2-local-proxy-routing",
            "steps": [
              "local-proxy-listener"
            ],
            "status": "covered"
          },
          {
            "stage": "impact-ddos-flooding",
            "steps": [
              "kimwolf-c2-outbound-floods"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-adb-misuse",
            "reason": "Belongs to another part of the 'Kimwolf v7: An Evolution of the Kimwolf Botnet' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-malware-installation",
            "reason": "Belongs to another part of the 'Kimwolf v7: An Evolution of the Kimwolf Botnet' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "defense-evasion-process-masquerading",
            "reason": "Belongs to another part of the 'Kimwolf v7: An Evolution of the Kimwolf Botnet' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "IoT or Android devices in the environment are infected with Kimwolf v7, as indicated by a local proxy listener on port 23075 and Ethereum Name Service (ENS) resolution used to bypass traditional C2 infrastructure takedowns.",
        "blind_spots": [
          {
            "id": "tor-backup-blind-spot",
            "risk": "If ENS resolution fails, the botnet reverts to Tor routing via a local proxy; standard DNS monitoring will not see this fallback activity.",
            "stage": "c2-local-proxy-routing",
            "question": "Is the malware actively using the hard-coded Tor .onion backup for C2 communication?",
            "requires": "Network flow logs with SNI or full proxy inspection"
          },
          {
            "id": "http2-fingerprint-visibility",
            "risk": "While high connection counts are visible, the stealthy HTTP/2 browser fingerprinting may blend into normal traffic if the environment has high baseline web usage.",
            "stage": "impact-ddos-flooding",
            "question": "Does the DDoS traffic exactly match the Chrome fingerprints reported in the research?",
            "requires": "hb_http_activity with nghttp2 specific header metadata"
          }
        ],
        "scoping_notes": "Target Android TV boxes, set-top boxes, and Linux-based IoT segments. These devices are the primary beachhead for Kimwolf v7 and are less likely to perform legitimate Ethereum RPC queries.",
        "beyond_detection": "A standard detection rule might alert on a single C2 IP, but this hunt correlates the modular internal proxy routing (port 23075), the rare use of Ethereum RPC services for domain resolution on IoT hosts, and the resulting high-cardinality outbound traffic spikes. This multi-stage correlation captures a functional bot presence that simple indicator matches miss."
      }
    },
    {
      "id": "local-proxy-listener",
      "type": "query",
      "label": "Local Proxy Traffic Routing",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_port, COUNT(*) AS connections, MIN(time) AS first_seen FROM hb_network_connection WHERE (dst_endpoint_ip = '127.0.0.1' OR dst_endpoint_ip = '::1') AND dst_endpoint_port = {{proxy_port}} AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, dst_endpoint_port",
        "surface": "hb_network_connection",
        "description": "Identify the Kimwolf local proxy architecture by finding internal network connections to the hard-coded loopback port 23075.",
        "expected_signal": "Internal connections to port 23075, likely originating from a masqueraded process. Silence indicates no local proxy routing on this port was observed."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Local Proxy Traffic Routing",
        "reads": [
          "device_hostname",
          "process_name",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_port, COUNT(*) AS connections, MIN(time) AS first_seen FROM hb_network_connection WHERE (dst_endpoint_ip = '127.0.0.1' OR dst_endpoint_ip = '::1') AND dst_endpoint_port = {{proxy_port}} AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, dst_endpoint_port",
        "silence": "not_evidence_of_absence",
        "expected": "Internal connections to port 23075, likely originating from a masqueraded process. Silence indicates no local proxy routing on this port was observed.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "ens-rpc-dns-resolution",
      "type": "query",
      "label": "Ethereum RPC and ENS DNS Resolution",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, query_hostname, query_type, answers, COUNT(*) AS count FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR (query_type = 'TXT' AND (LOWER(query_hostname) LIKE '%eth%' OR LOWER(query_hostname) LIKE '%rpc%'))) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, query_hostname, query_type, answers",
        "surface": "hb_dns_activity",
        "description": "Detect queries to public Ethereum RPC gateways or high-volume TXT record lookups used for resilient ENS-based C2 resolution.",
        "expected_signal": "DNS queries targeting legitimate Ethereum RPC services from non-developer hosts. Silence suggests no blockchain-based resolution occurred via these domains."
      },
      "parents": [
        {
          "id": "local-proxy-listener"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Ethereum RPC and ENS DNS Resolution",
        "reads": [
          "device_hostname",
          "process_name",
          "query_hostname",
          "query_type",
          "answers",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, query_hostname, query_type, answers, COUNT(*) AS count FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR (query_type = 'TXT' AND (LOWER(query_hostname) LIKE '%eth%' OR LOWER(query_hostname) LIKE '%rpc%'))) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, query_hostname, query_type, answers",
        "silence": "not_evidence_of_absence",
        "expected": "DNS queries targeting legitimate Ethereum RPC services from non-developer hosts. Silence suggests no blockchain-based resolution occurred via these domains.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "kimwolf-c2-outbound-floods",
      "type": "query",
      "label": "C2 Connections and Network Floods",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, COUNT(*) AS conn_count, MAX(time) AS last_seen FROM hb_network_connection WHERE (instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR (direction = 'outbound' AND disposition = 'Allowed')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, dst_endpoint_ip HAVING (instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR conn_count > 500)",
        "surface": "hb_network_connection",
        "description": "Identify direct communication with known Kimwolf infrastructure or anomalous high-volume outbound network bursts indicative of DDoS activity.",
        "expected_signal": "Connections to Russian C2 IPs or a massive number of outbound connections from a single process to a single destination. Silence proves absence of massive floods during the window."
      },
      "parents": [
        {
          "id": "local-proxy-listener"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "C2 Connections and Network Floods",
        "reads": [
          "device_hostname",
          "process_name",
          "dst_endpoint_ip",
          "direction",
          "disposition",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, COUNT(*) AS conn_count, MAX(time) AS last_seen FROM hb_network_connection WHERE (instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR (direction = 'outbound' AND disposition = 'Allowed')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, dst_endpoint_ip HAVING (instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR conn_count > 500)",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Connections to Russian C2 IPs or a massive number of outbound connections from a single process to a single destination. Silence proves absence of massive floods during the window.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "weigh-kimwolf-evidence",
      "type": "analytic",
      "label": "Triage Kimwolf Indicators",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "local-proxy-listener",
          "ens-rpc-dns-resolution",
          "kimwolf-c2-outbound-floods"
        ],
        "objective": "Determine if any host is compromised by Kimwolf v7. Specifically, look for hosts that exhibit a local proxy listener on port 23075 while also performing Ethereum RPC DNS resolutions or communicating with the identified C2 IP addresses.",
        "description": "Correlate local proxy usage, ENS DNS queries, and outbound flood behavior to confirm a functional Kimwolf v7 infection.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict linking the loopback proxy to external infrastructure.",
        "success_criteria": "A verdict of malicious, suspicious, or benign per host citing the specific port and domain lookups."
      },
      "parents": [
        {
          "id": "ens-rpc-dns-resolution",
          "kind": "merge"
        },
        {
          "id": "kimwolf-c2-outbound-floods",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "kimwolf-decision",
      "type": "checkpoint",
      "label": "Kimwolf Infection Decision",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the weigh-kimwolf-evidence verdict is malicious for at least one host involving local proxy listeners and Ethereum-related DNS resolution",
        "condition": "the weigh-kimwolf-evidence verdict is malicious for at least one host involving local proxy listeners and Ethereum-related DNS resolution",
        "blind_spot": "tor-backup-blind-spot",
        "confidence": "high",
        "description": "Route the hunt based on the presence of high-confidence botnet indicators.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "weigh-kimwolf-evidence"
        }
      ]
    },
    {
      "id": "isolate-infected-host",
      "type": "action",
      "label": "Isolate Compromised Device",
      "config": {
        "target": "endpoint",
        "description": "Prevent further DDoS participation and stop C2 communication by isolating the host.",
        "instructions": "Isolate the identified host immediately to halt DDoS floods and rotate any credentials that may have been exposed through the local proxy.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "kimwolf-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-triage",
      "type": "task",
      "label": "Verify Botnet Triage",
      "config": {
        "assignee": "analyst",
        "description": "Manually verify the agent's findings and look for additional indicators such as the Tor backup service.",
        "instructions": "Review the DNS TXT records for ENS resolution patterns. Check the processes associated with port 23075 for masquerading behavior like 'netd_service'. Investigate if any outbound traffic is routing through non-standard ports to known Tor gateways."
      },
      "parents": [
        {
          "id": "kimwolf-decision",
          "branch": "default"
        },
        {
          "id": "kimwolf-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "kimwolf-decision",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-infected-host"
        }
      ]
    },
    {
      "id": "close-out-hunt",
      "type": "task",
      "label": "Close-out and Tune Detections",
      "config": {
        "assignee": "analyst",
        "description": "Document the hunt outcome and propose detections for blockchain-based C2 resolution.",
        "instructions": "Log the identified C2 IPs and domains. Propose a rule for monitoring high-frequency ENS gateway lookups from IoT and Android TV segments."
      },
      "parents": [
        {
          "id": "analyst-triage"
        }
      ]
    }
  ]
}