When the domain entry differs between what is presented in the
SNI (server name indication) and HTTP payloads, the firewall generates
a threat log with a unique threat ID of 86467 (as a Spyware signature).
To provide a context for threat assessment purposes, the threat
log contains the spoofed SNI domain in the URL/Filename (misc)
threat log field, which
is expressed as
URL
in the threat log. A
corresponding URL log showing the HTTP host header in the
URL
field,
is also available, which can be found by searching for the matching
session ID.